Box wants to let businesses control cloud encryption keys “this year”

Box CEO Aaron Levie told Ars last September that the cloud storage company is trying to build a service that would let customers store data in Box data centers but would keep encryption keys in-house. Today, he said it might be available before the end of this year.

Such a system could make it impossible for Box to turn customer data over to the government in a readable format. In the history of our entire company this has never happened to an enterprise customer, he said, referring to blind subpoenas in which the government demands access to a customers data without that customer being told. But government requests are still a risk.

We are working on an encryption key solution right now. Were still figuring out the exact details of how we want to integrate it with a customer environment. We do see that for very large or sensitive organizations that this is going to be an important solution for them, he said.

Levie wasnt ready to promise an actual product last September, noting that its hard to design without undermining the Box collaboration tools that make storing data with the company a worthwhile proposition. Box has apparently made some progress, though, as today he said the more secure service is on the roadmap right now I think were looking at this year, probably.

Levie was speaking during a Q&A at the InformationWeek Conference in Las Vegas, which is being hosted alongside the annual Interop show.

This is something we want to get right, so there's a lot of moving pieces, he said. Were very sympathetic to the issue of encryption keys; we respect that there are definitely environments where its really important.

Last year, Levie told Ars that Box is architecturally similar to "Google or Microsoft in that we are encrypting all the data on both transit and storage, but we obviously have to manage the encryption key, because as a collaborative application we have to broker that exchange between multiple users. To make it a seamless experience, it requires us to have those keys."

There are ways for businesses to use collaborative cloud storage services without trusting encryption to the provider. One product called Syncdocs encrypts files users store on Google Drive, but it comes with some tradeoffs. If you forget your password, there is no known way to recover your data or password, Syncdocs says in an FAQ. This also removes the ability to access files in the Google Drive browser interface, so you need a secure program on your PC to access them, the company says. We are working on Web browser access, but it will not be as secure.

WatchDox, an enterprise file sharing and collaboration company that competes against Box, offers both cloud storage and virtual appliances that customers can use to secure data on their own hardware. In one scenario, customers can control encryption keys in a hardware security module that is in the customer's facilities but connects to the cloud storage in WatchDoxs data centers, similar to the service Levie wants to build. WatchDox described this capability to Ars last year, but it doesnt appear to be as heavily advertised as WatchDoxs other services.

A new company called Tresorit last year also started offering cloud-based collaboration with encryption being taken care of on customer's devices before being uploaded to the cloud. Additionally, CipherCloud adds security features to Box "while giving you exclusive control over your encryption keys." Once uploaded to Box, files can be accessed and decrypted by authorized users.

See the rest here:
Box wants to let businesses control cloud encryption keys “this year”

Study Shows Flawed U.S. Encryption Standard Could Be Broken in Seconds

If the NSA did have the keys to the backdoor in a random number generator it could break some encryption without trouble.

The security of a data connection protected using a flawed U.S. encryption standard promoted by the National Security Agency could be broken in under 16 seconds using a single computer processor. Thats according to the first in-depth study of how easily encryption systems that use the now deprecated Dual_EC random number generator could be defeated by an attacker that had backdoored the standard.

The flawed standard has never been widely used to protect Internet communications, even though the security company RSA got $10 million from the NSA to make it the default random number generator in one of its software packages. It is not known whether the NSA or anyone else knows the crucial mathematical relationship needed to exploit the flaw and undo encryption based on Dual_EC.

However, the study conclusively shows that an attacker that did know the key to the Dual_EC backdoor could put it to practical use. Not all of the six different encryption software packages tested could be defeated in seconds: half took a 16-processor cluster between 60 and 80 minutes of work to break. But a national intelligence agency could significantly improve on those times by devoting more computing power to the problem.

Documents leaked by Edward Snowden, and published in September 2013, do indicate that the NSA has tried to influence standards on encryption, and to encourage commercial companies to make security products more susceptible to U.S. surveillance. Both the National Institute of Standards and Technology (NIST) and RSA withdrew their endorsement for Dual_EC after the Snowden documents were published last year.

The new study was carried out by researchers from Johns Hopkins University, the University of Wisconsin, the Technical Univesity of Eindhoven, the University of Illinois at Chicago, and the University of California San Diego.

NIST first proposed Dual_EC in 2006. Months later two researchers from Microsoft found a mathematical flaw that resembled an intentional backdoor that could be used to undo encryption based on the standard.

The weakness centers on two constants, known as P and Q, that function as kind of default settings for the generator and are supposed to be randomly chosen and unrelated to one another. However if there is some mathematical relationship between the two, it can be used to predict the output of the generator based on seeing one of its past outputs.

Some security experts have long suspected that the versions of P and Q in NISTs version of Dual_EC are linked in some way, and that the NSA knows exactly how, allowing it to undo encryption based on the standard. Those fears gained credence in light of the fact that the Snowden documents showed that the agency did have a policy of trying to influence new standards.

To test what a key to the backdoor in Dual_EC might allow, the researchers set values of P and Q that were linked. They then played the role of an attacker trying to break encrypted TLS connections made by software in use today that supports Dual_EC or once used it by default. TLS connections are widely used to secure Internet data, such as Web browsing, e-mail, and VoIP.

The rest is here:
Study Shows Flawed U.S. Encryption Standard Could Be Broken in Seconds

Google trumpets extra encryption for Gmail, but stays mum on other apps

Google recently trumpeted that it now encrypts Gmail messages while shuffling them among its data centers, an extra security layer aimed at thwarting government and criminal snoops, but didnt say if it applies this protection to its other applications.

Asked for clarification, the company declined to comment. We dont have more details to share beyond the Gmail news, but were always working in strengthening and encrypting across more services and links, a spokeswoman said via email.

Googles reluctance to clarify the scope of its internal encryption is baffling and does a disservice to enterprise customers who rely on the Apps suite for workplace communication, cloud storage and collaboration, according to analysts.

When confronted with the evidenceof a compromise, and asked for an explanation as to how it happened and what they are doing about it, Google is dissembling. This is no basis for trust, said Jay Heiser, a Gartner analyst.

Edward Snowden

At issue are reports from last year, based on leaks from former National Security Agency (NSA) contractor Edward Snowden, that the agency snooped on users of online services in part by intercepting data Internet companies transmitted unencrypted in plain text among their own servers and data centers.

Back in September, Google officials told The Washington Post that the company was accelerating efforts to encrypt communications between its data centers as a result of these reports.

Its an arms race, Eric Grosse, vice president for security engineering at Google, said at the time.

About two weeks ago, Google announced it had turned on this internal encryption for Gmail, but glaringly neglected to address if and when this will be done for its other services and applications.

Every single email message you send or receive100 percent of themis encrypted while moving internally. This ensures that your messages are safe not only when they move between you and Gmails servers, but also as they move between Googles data centerssomething we made a top priority after last summers revelations, the Google post reads.

View original post here:
Google trumpets extra encryption for Gmail, but stays mum on other apps

Google touts extra encryption for Gmail, remains mum on other apps

News

By Juan Carlos Perez

April 1, 2014 03:14 PM ET

IDG News Service - Google recently trumpeted that it now encrypts Gmail messages while shuffling them among its data centers, an extra security layer aimed at thwarting government and criminal snoops, but didn't say if it applies this protection to its other applications.

Asked for clarification, the company declined to comment. "We don't have more details to share beyond the Gmail news, but we're always working in strengthening and encrypting across more services and links," a spokeswoman said via email.

Google's reluctance to clarify the scope of its internal encryption is baffling and does a disservice to enterprise customers who rely on the Apps suite for workplace communication, cloud storage and collaboration, according to analysts.

"When confronted with the evidence of a compromise, and asked for an explanation as to how it happened and what they are doing about it, Google is dissembling. This is no basis for trust," said Jay Heiser, a Gartner analyst.

At issue are reports from last year, based on leaks from former National Security Agency (NSA) contractor Edward Snowden, that the agency snooped on users of online services in part by intercepting data Internet companies transmitted unencrypted in "plain text" among their own servers and data centers.

Back in September, Google officials told The Washington Post that the company was accelerating efforts to encrypt communications between its data centers as a result of these reports.

"It's an arms race," Eric Grosse, vice president for security engineering at Google, said at the time.

Visit link:
Google touts extra encryption for Gmail, remains mum on other apps