{"id":13595,"date":"2014-04-02T16:41:28","date_gmt":"2014-04-02T20:41:28","guid":{"rendered":"http:\/\/www.opensource.im\/?p=13595"},"modified":"2014-04-02T16:41:28","modified_gmt":"2014-04-02T20:41:28","slug":"box-wants-to-let-businesses-control-cloud-encryption-keys-this-year","status":"publish","type":"post","link":"https:\/\/euvolution.com\/open-source-convergence\/encryption\/box-wants-to-let-businesses-control-cloud-encryption-keys-this-year.php","title":{"rendered":"Box wants to let businesses control cloud encryption keys \u201cthis year\u201d"},"content":{"rendered":"<p><p>    Box CEO Aaron Levie     told Ars last September that the cloud storage company is    trying to build a service that would let customers store data    in Box data centers but would keep encryption keys in-house.    Today, he said it might be available before the end of this    year.  <\/p>\n<p>    Such a system could make it impossible for Box to turn customer    data over to the government in a readable format. In the    history of our entire company this has never happened to an    enterprise customer, he said, referring to blind subpoenas    in which the government demands access to a customers data    without that customer being told. But government requests are    still a risk.  <\/p>\n<p>    We are working on an encryption key solution right now. Were    still figuring out the exact details of how we want to    integrate it with a customer environment. We do see that for    very large or sensitive organizations that this is going to be    an important solution for them, he said.  <\/p>\n<p>    Levie wasnt ready to promise an actual product last September,    noting that its hard to design without undermining the Box    collaboration tools that make storing data with the company a    worthwhile proposition. Box has apparently made some progress,    though, as today he said the more secure service is on the    roadmap right now I think were looking at this year,    probably.  <\/p>\n<p>    Levie was speaking during a Q&A at the InformationWeek    Conference in Las Vegas, which is being hosted alongside    the annual Interop show.  <\/p>\n<p>    This is something we want to get right, so there's a lot of    moving pieces, he said. Were very sympathetic to the issue    of encryption keys; we respect that there are definitely    environments where its really important.  <\/p>\n<p>    Last year, Levie told Ars that Box is architecturally similar    to \"Google or Microsoft in that we are encrypting all the data    on both transit and storage, but we obviously have to manage    the encryption key, because as a collaborative application we    have to broker that exchange between multiple users. To make it    a seamless experience, it requires us to have those keys.\"  <\/p>\n<p>    There are ways for businesses to use collaborative cloud    storage services without trusting encryption to the provider.    One product called Syncdocs encrypts files users store on    Google Drive, but it comes with some tradeoffs. If you forget    your password, there is no known way to recover your data or    password, Syncdocs    says in an FAQ. This also removes the ability to access    files in the Google Drive browser interface, so you need a    secure program on your PC to access them, the company says.    We are working on Web browser access, but it will not be as    secure.  <\/p>\n<p>        WatchDox, an enterprise file sharing and collaboration    company that competes against Box, offers both cloud storage    and virtual appliances that customers can use to secure data on    their own hardware. In one scenario, customers can control    encryption keys in a hardware security module that is in the    customer's facilities but connects to the cloud storage in    WatchDoxs data centers, similar to the service Levie wants to    build. WatchDox described this capability to Ars last year, but    it doesnt appear to be as heavily advertised as WatchDoxs    other services.  <\/p>\n<p>    A new company called Tresorit last    year also started offering cloud-based collaboration with    encryption being taken care of on customer's devices before    being uploaded to the cloud. Additionally, CipherCloud    adds security features to Box \"while giving you exclusive    control over your encryption keys.\" Once uploaded to Box, files    can be accessed and decrypted by authorized users.  <\/p>\n<p><!-- Auto Generated --><\/p>\n<p>See the rest here:<br \/>\n<a target=\"_blank\" href=\"http:\/\/arstechnica.com\/information-technology\/2014\/04\/box-wants-to-let-businesses-control-cloud-encryption-keys-this-year\/\/RS=^ADA1syTSPyOHfOjaTfwzVCA4C68cYU-\" title=\"Box wants to let businesses control cloud encryption keys \u201cthis year\u201d\">Box wants to let businesses control cloud encryption keys \u201cthis year\u201d<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Box CEO Aaron Levie told Ars last September that the cloud storage company is trying to build a service that would let customers store data in Box data centers but would keep encryption keys in-house. <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[45],"tags":[],"class_list":["post-13595","post","type-post","status-publish","format-standard","hentry","category-encryption"],"_links":{"self":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/13595"}],"collection":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/comments?post=13595"}],"version-history":[{"count":0,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/13595\/revisions"}],"wp:attachment":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/media?parent=13595"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/categories?post=13595"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/tags?post=13595"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}