{"id":471,"date":"2016-02-28T16:26:35","date_gmt":"2016-02-28T22:26:35","guid":{"rendered":"http:\/\/pkeating.com\/?p=471"},"modified":"2016-02-28T16:27:33","modified_gmt":"2016-02-28T22:27:33","slug":"a-better-encryption-mousetrap","status":"publish","type":"post","link":"https:\/\/pkeating.com\/?p=471","title":{"rendered":"A Better Encryption Mousetrap?"},"content":{"rendered":"<p><span style=\"color: #000000; font-family: Calibri;\">Some businesses object to the use of cloud storage of electronic data because of a fear that employees of the storage provider (or others) could access the businesses\u2019 data stored in the cloud.\u00a0 Even if the data is encrypted, this fear can still exist if the cloud storage service holds the key necessary to decrypt the data.\u00a0 <\/span><!--more--><\/p>\n<p><span style=\"color: #000000; font-family: Calibri;\">In\u00a0a 2015 <a href=\"http:\/\/pkeating.com\/?p=93#more-93\">post<\/a>, I wrote about the options available to encrypt data through a method that will prevent the cloud storage provider from accessing the data.\u00a0 At that time, the user needed to retain the services of a third-party encryption service such as Sookasa or Boxcryptor to encrypt data before it was loaded into the cloud.\u00a0 This is a functional approach, but it is cumbersome because the user must hire two separate service providers to get the job done \u2013 a cloud storage provider and a separate encryption provider.<\/span><\/p>\n<p><span style=\"color: #000000; font-family: Calibri;\">The New Year brings increased ease of use for customers of Box, which is one of the major cloud storage providers.\u00a0 Box now offers its \u201cKeySafe\u201d service to customers who wish to prevent Box from being able to decrypt the customer\u2019s data.\u00a0 To allow customers to do so without having to retain a third party service to store data encryption keys, Box partnered with Amazon Web Services (\u201cAWS\u201d).\u00a0 Customers who elect this level of protection will have an additional layer of encryption placed on their data stored in Box.\u00a0 The first level is the standard encryption that Box places on all customer data.\u00a0 Box will retain that decryption key.\u00a0 The second level of encryption will be performed with the customer\u2019s decryption key, which will be stored with AWS.\u00a0 Box will not have access to the customer\u2019s key.<\/span><\/p>\n<p><span style=\"color: #000000; font-family: Calibri;\">An analogy to explain this approach is the two-key method of launching nuclear missiles.\u00a0 To avoid the risk of one rogue person performing a missile launch without authority, two authorized people must activate the launch by each inserting and turning their key in the launch mechanism.\u00a0 Box\u2019s Keysafe approach is similar.\u00a0 To access the data, both the key maintained by Box and the key maintained by AWS must be used.\u00a0 Box states that only the customer will be able to make that happen.<\/span><\/p>\n<p><span style=\"color: #000000; font-family: Calibri;\">This new security feature in Box should be appealing to businesses with a heightened need to secure their data or the data of third parties.\u00a0 For example, health care providers or law firms handling particularly sensitive client information. <\/span><\/p>\n<div class=\"twttr_buttons\"><div class=\"twttr_followme\">\n\t\t\t\t\t\t<a href=\"https:\/\/twitter.com\/@_PatrickKeating\" class=\"twitter-follow-button\" data-show-count=\"false\" data-size=\"default\"  data-show-screen-name=\"false\"  target=\"_blank\">Follow me<\/a>\n\t\t\t\t\t<\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Some businesses object to the use of cloud storage of electronic data because of a fear that employees of the storage provider (or others) could access the businesses\u2019 data stored in the cloud.\u00a0 Even if the data is encrypted, this fear can still exist if the cloud storage service holds the key necessary to decrypt [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":275,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false},"categories":[17,5,6],"tags":[],"jetpack_featured_media_url":"https:\/\/i1.wp.com\/pkeating.com\/wp-content\/uploads\/2015\/05\/Locked-Monitor.jpg?fit=275%2C275&ssl=1","jetpack_publicize_connections":[],"jetpack_shortlink":"https:\/\/wp.me\/p52Eew-7B","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/pkeating.com\/index.php?rest_route=\/wp\/v2\/posts\/471"}],"collection":[{"href":"https:\/\/pkeating.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pkeating.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pkeating.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pkeating.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=471"}],"version-history":[{"count":2,"href":"https:\/\/pkeating.com\/index.php?rest_route=\/wp\/v2\/posts\/471\/revisions"}],"predecessor-version":[{"id":473,"href":"https:\/\/pkeating.com\/index.php?rest_route=\/wp\/v2\/posts\/471\/revisions\/473"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/pkeating.com\/index.php?rest_route=\/wp\/v2\/media\/275"}],"wp:attachment":[{"href":"https:\/\/pkeating.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=471"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pkeating.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=471"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pkeating.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=471"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}