{"id":93,"date":"2014-09-21T18:20:29","date_gmt":"2014-09-21T18:20:29","guid":{"rendered":"http:\/\/pkeating.com\/?p=93"},"modified":"2015-04-06T14:52:26","modified_gmt":"2015-04-06T20:52:26","slug":"lock-it-up-encrypt-your-cloud-data-2","status":"publish","type":"post","link":"https:\/\/pkeating.com\/?p=93","title":{"rendered":"Lock it Up! Encrypt Your Cloud Data"},"content":{"rendered":"<p>In my last <a title=\"Lost in the Clouds\" href=\"http:\/\/pkeating.com\/?p=48\" target=\"_blank\">post<\/a>, I discussed whether data maintained in a cloud storage or computing platform can be said to be confidential.\u00a0 This is important because the Texas Uniform Trade Secrets Act requires the owner of a trade secret to undertake reasonable steps to maintain the confidentiality of the trade secret.\u00a0 I am not aware of a reported case opinion analyzing how to satisfy that requirement for data stored in the cloud.\u00a0 Therefore, we do not yet know whether Texas courts will require a user of cloud storage or computing services to take extra precautions to protect the secrecy of their trade secrets.\u00a0 Nevertheless, because encryption is a relatively easy solution to the problem of cloud service providers having the ability to access or disclose their customers data, it strikes me as a smart business practice to take advantage of that solution.<!--more--><\/p>\n<p>Encryption is a method of encoding data.\u00a0 Once the data is encoded with a strong encryption algorithm, a reader can only understand the data by possessing the key necessary to decrypt the data.\u00a0 In this sense, the data is locked.\u00a0 \u201cDecryption\u201d unlocks the data and turns the data back into its original, accessible format.<\/p>\n<p>The strongest type of encryption used in the United States is known as 256 bit AES encryption.\u00a0 How it works is complicated.\u00a0 That is good though because if it was simple, the lock would be easy to pick.\u00a0 For this post, it is sufficient to say that 256 bit AES encryption works and provides the user with a very strong lock.\u00a0 However, if you are like me and are always curious about how things work, you can learn more about encryption at: (1) <a title=\"Dean's Article\" href=\"http:\/\/www.12robots.com\/index.cfm\/2010\/4\/27\/Cryptography-Part-1--Getting-Started--Security-Series-16\" target=\"_blank\">part 1 of 4<\/a> in Jason Dean\u2019s blog posts explaining encryption\u00a0and (2) for good visual examples of how encryption works, pages 26-49 of his <a title=\"Powerpoint Presentation\" href=\"http:\/\/www.12robots.com\/enclosures\/DeanJason-cfObjective2010Crypto.pdf\" target=\"_blank\">PowerPoint presentation<\/a>.<\/p>\n<p>There are three services for encrypting data stored in the cloud that I find to be user friendly.\u00a0 Each service uses 256 bit AES encryption.\u00a0 You can try out each service for free by downloading their programs from their websites.\u00a0 Once you encrypt your cloud data with one of these services, the cloud service provider (or anyone else who obtains access to the data) will not be able to read it.<\/p>\n<p><strong><a title=\"Boxcryptor Website\" href=\"https:\/\/www.boxcryptor.com\/\" target=\"_blank\">Boxcryptor<\/a> and <a title=\"Sookasa Website\" href=\"http:\/\/www.sookasa.com\" target=\"_blank\">Sookasa<\/a><\/strong><\/p>\n<p>Boxcryptor and Sookasa work by encrypting data on your computer before the data is transmitted to the cloud service provider\u2019s servers.\u00a0 Boxcryptor and Sookasa hold the key necessary to decrypt (unlock) the data.\u00a0 You choose a password to secure access to that key.\u00a0 Neither Boxcryptor nor Sookasa will have access to your data because it is stored with your cloud service provider.\u00a0 Thus, even if they were to gain access to your decryption key, they could not access your data.<\/p>\n<p>I tested Boxcryptor and Sookasa with Dropbox.\u00a0 They both work by installing a new folder in the Dropbox folder on your computer.\u00a0 All of the files that you place into that folder are encrypted before your computer uploads the files to the cloud.\u00a0 You can still open the files on your computer and view them.\u00a0 You don\u2019t have to type in the decryption key to do that.\u00a0 Boxcryptor and Sookasa handle decryption for you automatically.\u00a0 You can also choose to share your encrypted files with others.<\/p>\n<p>Both Boxcryptor and Sookasa offer free \u201capps\u201d for installation on smartphones and tablets so that you may access your encrypted data in the cloud through those devices.<\/p>\n<p>Boxcryptor\u2019s description of its service can be seen <a title=\"Boxcryptor Description\" href=\"https:\/\/www.boxcryptor.com\/en\/boxcryptor\" target=\"_blank\">here<\/a>.\u00a0 The big factor that Boxcryptor has in its favor is flexibility.\u00a0 Boxcryptor <a title=\"Boxcryptor Compatability List\" href=\"https:\/\/www.boxcryptor.com\/en\/provider\" target=\"_blank\">advertises<\/a> that it works with all of the major cloud services (Dropbox, Google Drive, Box and many more).\u00a0 However, I did not see Amazon\u2019s cloud drive listed in Boxcryptor\u2019s list.\u00a0 Regardless, Boxcryptor will be attractive to people who are already using a cloud service other than Dropbox and do not want to change.<\/p>\n<p>Sookasa\u2019s selling point is its advertised HIPAA and FERPA compliance.\u00a0 By way of example, Sookasa allows the user to create an audit trail for file access and to revoke a previously authorized person\u2019s access to files.\u00a0 The drawback of Sookasa as of the date of this post is that it only works with Dropbox.<\/p>\n<p>Between the two, I found Sookasa to be more cleanly integrated with Dropbox and to have a better user interface.\u00a0 For example, with Sookasa, I could use Dropbox in the same manner I always have \u2013 open my Dropbox folder on my computer; place a file in the Sookasa sub-folder in my Dropbox folder; and the file becomes encrypted automatically.\u00a0 With Boxcryptor, however, I had to be careful to remember to access Boxcryptor\u2019s folder in Dropbox by first clicking on the Boxcryptor symbol on the bottom right of my Windows desktop.\u00a0 Doing this opened a window to the Boxcryptor folder in Dropbox and all files placed in the folder encrypted automatically.\u00a0 However, if I accessed that same folder directly through Dropbox and placed a file in the folder, the file would not automatically encrypt.\u00a0 My fear is that this increases the chance of a user error allowing non-encrypted files to make it into the cloud.<\/p>\n<p><a title=\"Spider Oak Website\" href=\"https:\/\/spideroak.com\/?utm_expid=14446725-6.kmcEPnsiSaevBSQb7kScng.0&amp;utm_referrer=https%3A%2F%2Fwww.google.com%2F\" target=\"_blank\"><strong>Spider Oak<\/strong><\/a><\/p>\n<p>The first thing to know about Spider Oak is that it is a cloud storage provider.\u00a0 Spider Oak is not a service for encrypting data stored on other cloud service providers\u2019 servers.\u00a0 With Spider Oak, the customer uses Spider Oak\u2019s cloud servers and Spider Oak encrypts the data.\u00a0 Although Spider Oak holds its customers\u2019 data in encrypted form, Spider Oak states that it cannot access the key necessary to decrypt the data because that key is also encrypted before the user sends the key to Spider Oak.\u00a0 Spider Oak\u2019s marketing slang for this method of securing data and the encryption key is \u201cZero Knowledge.\u201d\u00a0 You can read learn more about how they protect the decryption keys <a title=\"Zero Knowledge Description\" href=\"https:\/\/spideroak.com\/faq\/questions\/23\/is_spideroak_really_zero_knowledge_could_you_read_a_users_data_if_forced_at_gunpoint\/\" target=\"_blank\">her<\/a>e\u00a0and <a title=\"In-depth: How Spider Oak Works\" href=\"https:\/\/spideroak.com\/engineering_matters\" target=\"_blank\">here<\/a>.<\/p>\n<p>Spider Oak\u2019s selling point is that it is a one stop shop for cloud storage and encryption.\u00a0 The downside though is that, with Spider Oak, the customer cannot use Spider Oak\u2019s encryption technology on data stored with one of the larger cloud service providers.<\/p>\n<p>Spider Oak also offers \u201capps\u201d to permit its customers to access their files on IOS and Android operating system devices.<\/p>\n<p><strong>Conclusion<\/strong><\/p>\n<p>Before storing sensitive business information that you consider to be a trade secret in the cloud, make sure that the data will be secure.\u00a0 To be entitled to protection under the Texas Uniform Trade Secrets Act, the owner of the information must have undertaken efforts that are reasonable under the circumstances to maintain its secrecy.\u00a0 While I am not aware of a reported case decision yet addressing whether data stored in a third party cloud service must be encrypted to qualify as a trade secret, encrypting sensitive data strikes me as a smart business practice.<\/p>\n<p>&nbsp;<\/p>\n<p><em>Photograph by Robert S. Donovan displayed pursuant to the license located at:<\/em><\/p>\n<p><a href=\"https:\/\/creativecommons.org\/licenses\/by\/2.0\/legalcode\"><em>https:\/\/creativecommons.org\/licenses\/by\/2.0\/legalcode<\/em><\/a><\/p>\n<div class=\"twttr_buttons\"><div class=\"twttr_followme\">\n\t\t\t\t\t\t<a href=\"https:\/\/twitter.com\/@_PatrickKeating\" class=\"twitter-follow-button\" data-show-count=\"false\" data-size=\"default\"  data-show-screen-name=\"false\"  target=\"_blank\">Follow me<\/a>\n\t\t\t\t\t<\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>In my last post, I discussed whether data maintained in a cloud storage or computing platform can be said to be confidential.\u00a0 This is important because the Texas Uniform Trade Secrets Act requires the owner of a trade secret to undertake reasonable steps to maintain the confidentiality of the trade secret.\u00a0 I am not aware [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":104,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false},"categories":[17,5,6],"tags":[],"jetpack_featured_media_url":"https:\/\/i2.wp.com\/pkeating.com\/wp-content\/uploads\/2014\/09\/Masterd-small-by-Robert-Donovon.jpg?fit=320%2C320&ssl=1","jetpack_publicize_connections":[],"jetpack_shortlink":"https:\/\/wp.me\/p52Eew-1v","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/pkeating.com\/index.php?rest_route=\/wp\/v2\/posts\/93"}],"collection":[{"href":"https:\/\/pkeating.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pkeating.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pkeating.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pkeating.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=93"}],"version-history":[{"count":5,"href":"https:\/\/pkeating.com\/index.php?rest_route=\/wp\/v2\/posts\/93\/revisions"}],"predecessor-version":[{"id":103,"href":"https:\/\/pkeating.com\/index.php?rest_route=\/wp\/v2\/posts\/93\/revisions\/103"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/pkeating.com\/index.php?rest_route=\/wp\/v2\/media\/104"}],"wp:attachment":[{"href":"https:\/\/pkeating.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=93"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pkeating.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=93"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pkeating.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=93"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}