
Many people have changed traditional office solutions to work with online services. This is reliable: even if the house suddenly turns off electricity, the text will not disappear. This is insurance for the theft or seizure of a laptop. This is convenient for collaboration: you do not need to send documents to each other, just "shake".
Some of my friends completely switched to work on the network. Their computers turned into "clean" devices. In addition to the operating system, a favorite browser and several applied programs on such a computer, there is nothing to be interested in fans of poke their nose into other people's affairs.
On the other hand, many people use cloud storages literally - store files. For example, photos from trips or important documents.
According to Cloud Storage Market Research Report , from 2020 to 2025, the cloud solution market will develop rapidly. An annual increase will be almost 25%. In this article, we will talk about the simplest solutions for ordinary users, without affecting the state and corporate spheres.
If you believe the SOPHOS study , the vast majority (96%) of companies storing important data in the cloud are worried about safety. And not in vain: about 70% of respondents note problems with data leaks. Some note the deterioration of the situation in recent years. So, the Thales Cloud Security Study report noted that 45% of enterprises in 2022 were faced with a cloud data leak or could not take an audit in this part. This is 5% more than in the previous year.
"Some kind of hellish hole!" - exclaim the reader. Nothing special. Cloud storages are subject to the same threats as other sites. The attackers can hack them. Errors occur in server configuration. Sometimes there is a lack of safety measures. For example, there is no double -factor authentication . Or there is this option, but for some reason the user does not resort to it. And so on - up to the drain of data through an insider, an employee of the cloud provider.
In December 2020, a group of cyber zlodes, calling themselves Clop, abducted dozens of gigabytes of private data at the cloud provider Accallion. Hackers took advantage of the vulnerability in the outdated file download program into the cloud. For the confidential data obtained in this way, the villains demanded a ransom. Otherwise, they threatened to publish data on the network. Among the victims were the University of Colorado, the Reserve Bank of New Zealand, the Kroger supermarket chain (one of the largest in the world), Singapore telecommunication giant Singtel, Jones Day (in the twenty of the coolest legal companies in the United States).
In 2022, Fishers successfully attacked Dropbox. According to the official message of the company, customer files were not injured, but 130 code repositories, names and email addresses of employees and customers leaked.
The word "safe" has long acquired an important marketing meaning. The interest of users requires a response. Therefore, many cloud service providers assure that the distinguishing feature of their service is security. Here is what the veteran of the Dropbox market mentioned above writes: “Security is our priority. We use multi -level protection in all of our distributed and reliable cloud infrastructure. It doesn't matter who you are a private person or a team. Our cloud security measures provide the same standard for the protection of all your online data. ” And all in this spirit. An impressive user can serve a variety of functions under the guise of “exceptional protection”. For example, cross-platform .
Here are some criteria that may be significant for you when choosing a cloud if you value safety.
Each has its own model of threats, so a set of significant criteria for each has its own.
But what about encryption, you ask? There are two main approaches here.
The first approach is to delegate the encryption function of the cloud provider. And it is convenient. It is enough to install the provider application for data synchronization. Third -party programs are not needed.
Those who care about security are better to pay attention to cloud storage facilities based on the principle of “encryption with zero knowledge” ( “Zero Knowledge Encryption” ). Sometimes it is called "Client Side Encryption", encryption on the client side. Like through encryption ("End-to-end encryption") in communications. No one but you has encryption keys. The cloud provider has no access to your files. As an example of a cloud storage with encryption on the client’s side, you can cite the MeGA service, the servers of which are located in New Zealand.
But there are also disadvantages. In particular, you will have to believe your cloudy provider that encryption is carried out carefully, without vulnerabilities and “bookmarks”.
The second approach means that encryption occurs on your computer using a third -party program. The cloud provider does not deal with your non -encrypted data at all.
So you get a number of advantages. The main thing is that you yourself choose the encryption program that you trust, and completely stop worrying "how it is there, in the cloud."
Examples of such programs.
If your local context pushes you to a special care of security, it makes sense to pay attention to the second option and try to encrypt the data before loading into the cloud on your own.
The author expresses gratitude to the expert on digital security Mikhail Ivanovsky for valuable comments when updating the material.