8 ms·
CipherCloud Responds to the Crypto StackExchange Controversy
- deleted 13y ago[deleted]
- earlz 13y agoFavorite line in the whole thing "Some of the fundamental security features made available (e.g. full field encryption, randomization through IVs, etc.) were disabled because we were not comfortable sharing such IP on the internet while our patents are still pending" So, apparently they are going to be patenting padding/randomization in encryption and "full field encryption". Our patent system at work for obvious things.
- c0ur7n3y 13y agoSigh. The whole supposed purpose of patents is to encourage disclosure of the invention.
- rys 13y ago10 links to their own website in that post. Not even links to other content, just root links. I feel bad not having much more to add because I don't really understand their technology, but that really stood out. Probably some auto highlighter running amok.
- Finster 13y agoLooks like they stand firmly behind their DMCA takedown. EFF should slap them with a trout, as far as I'm concerned.
- TranceMan 13y agoCoral cache version as site seems to be struggling already: http://blog.ciphercloud.com.nyud.net/responding-to-the-myths-about-cipherclouds-encryption-technology/ http://blog.ciphercloud.com.nyud.net/responding-to-the-myths...
- shabble 13y agoDue to a malicious denial of service attack, likely by our competitors, in which they leverage forum-promulgated references, which through human-mediated multiple hyper-text transfer protocol requests to our blog hosting infrastructure, attempt to access proprietary information about our strategic positioning viz a viz current nonpositive media attention, we are unable to provide this patent pending document at this time. Our legal department will be shortly dispatching a DMCA infringement notice to all parties "mirroring" our content as a sign of our ongoing commitment to protecting our valuable intellectual properties against these thieves and scoundrels. If you should encounter any further difficulties with our information dissemination services, please sign the following non-disclosure agreement[1] and affix the supplied Fedex label to your firstborn. We aim to respond to all communications within 6 working months, as part of our Quality Commitment Assurance. [1] Whilst blood is preferred, red ink will suffice.
- gfosco 13y agoMay be honest, it's just very convenient. "That demo we have on our site to show off the technology? It's really crippled and doesn't actually show off the technology... We promise the real thing actually works! Oh, you want to hear about the DMCA takedown? That was just our legal team, you know how they can be!"
- zapdrive 13y agoAnd oh, about the forums.. it was just a bunch of jealous competitors trying to put us down.
- hluska 13y agoThat was my "favourite" part of the whole message.
- misnome 13y ago> It....doesn't actually show off the technology... We promise the real thing actually works! And would be happy to have a full and frank discussion about the way our system works.... as long as you sign this NDA!
- zapdrive 13y ago> A couple of recent discussions in a few board threads contributed to by our competitors have questioned CipherCloud’s approach to delivering cloud information protection. My BS meter is running high.
- pi18n 13y agoYou might want to recalibrate it; the mercury should have burst the tube at this point. Searching encrypted data is impossible without fully homomorphic encryption and fully homomorphic encryption is wildly impractical for use at present. "Contributed to by our competitors" -- if that's the case, the competitors are giving informative SO answers about crypto. Whereas they are engaging in censorious shenanigans. I, for one, prefer the "competitors'" contributions.
- zapdrive 13y agoContributed to by our "competitors", who are actually a lot more competitive than us.
- betterunix 13y ago"Searching encrypted data is impossible without fully homomorphic encryption" That is not true; a private information retrieval protocol can be used to search encrypted data: https://ieeexplore.ieee.org/xpls/abs_all.jsp?arnumber=5683316&tag=1 https://ieeexplore.ieee.org/xpls/abs_all.jsp?arnumber=568331... You could also use an oblivious RAM, although I do not think that is practical yet: http://eprint.iacr.org/2010/366.pdf http://eprint.iacr.org/2010/366.pdf
- pi18n 13y agoDon't those require that the client actually do the searching? (I couldn't devote enough time to read them now, so I only read the abstracts. Thank you, by the way, for sending the links; this kind of stuff is really interesting.) To be specific I mean a second party being able to search the data for arbitrary strings would mean the security of it was broken completely, and I thought this service was storing and searching without client input.
- DanBC 13y ago> Service Temporarily Unavailable > The server is temporarily unable to service your request due to maintenance downtime or capacity problems. Please try again later. Everything they do is destroying their reputation. Unfortunately, only among a few people who would have been suspicious anyway.
- hluska 13y agoIf you're interested in seeing what's left of their reputation, take a look at Google's cache of their page. Looks like some malware: http://webcache.googleusercontent.com/search?q=cache:http://blog.ciphercloud.com/responding-to-the-myths-about-cipherclouds-encryption-technology/ http://webcache.googleusercontent.com/search?q=cache:http://...
- zapdrive 13y agoThis is total BS. How is posting a few screen-grabs from their publicly available video a violation of their copyright? Isn't it considered fair use? I was expecting more on the lines of "we are sorry for the whole fiasco, our legal team acts independently whenever it feels like there is a violation", instead of him defending the DMCA. They used DMCA to try and censor a debate about their lies. Talking about DMCA, is it just me, or does anybody else think that government is always eager to pass copyright protection (aka censorship) laws, rather than passing laws to protect the citizens from corporate greed?
- wmf 13y agoThat's what the citizens get when they don't hire lobbyists.
- zapdrive 13y agoSo how can this be fixed?
- fuzzix 13y agoStep one, acquire billions of dollars...
- betterunix 13y agoStop voting for politicians who have proved themselves to be servants of lobbyists and corporations, start voting for these guys: https://en.wikipedia.org/wiki/Third_party_%28United_States%29 https://en.wikipedia.org/wiki/Third_party_%28United_States%2...
- zapdrive 13y agoWhats the guarantee these guys won't sell out?
- unabridged 13y ago
- Zarathust 13y agoI didn't follow this story. Where can I find more information about this "Controversy"?
- betterunix 13y agoBasically, someone called out CipherCloud on apparently bogus claims about what they provide (homomorphic encryption). CipherCloud responded with DMCA takedown notices. Now they are trying to explain their actions, with a lot of "trust us, we are only hiding the crypto details because we need to maintain a competitive advantage!"
- tveita 13y agoOne correction: I don't think CipherCloud have actually claimed to do homomorphic encryption - at least I can't find any such statement on their web site. That was an assumption on the part of the StackExchange user. It would be hard for them to make a security guarantee that isn't bogus, if the screenshots from their demo is an accurate representation of their technology, but they don't appear to have made this particular fraudulent statement.
- danbruc 13y agohttps://news.ycombinator.com/item?id=5579538 https://news.ycombinator.com/item?id=5579538
- bbatchelder 13y agoLink to the Crypto StackExchange thread: http://crypto.stackexchange.com/questions/3645/how-is-ciphercloud-doing-homomorphic-encryption http://crypto.stackexchange.com/questions/3645/how-is-cipher...
- pchowdhry 13y agoI'm a little confused about not wanting to disclose IP during a patent process. Isn't that what the patent process is designed to do? Disclose a novel invention, and have it (among other things) vetted for prior art. They say these patents are pending, in which case, shouldn't they be searchable? Has anyone found them? I did an albeit cursory search and couldn't find anything. I'd like to give these guys the benefit of the doubt as they are funded by a16z, but the lack of information is troubling.
- tptacek 13y agoWeasel wording filter: Graf 1, sentence 1: "a few board threads" -> Internet's current most important programming forum. Graf 1, sentence 1: "contributed to by our competitors" -> Smoke screen, unsupported, irrelevant. Graf 2, sentence 2: "basically admitted they really didn't know the facts" -> Because the facts weren't provided, the contributors set about reversing them from published material, the point of the thread. Graf 3, sentence 4: "does use publicly available, well researched, and NIST validated cryptographic algorithms" -> Virtually all cryptography anywhere can make a similar claim, and most of that code is broken. NIST validates primitives and a few basic constructions, but tying those primitives into a functional cryptosystem is outside their purview. Graf 4, sentence 1: "for any customer deployments" -> Leaves open the question of whether they implement semantically insecure constructions in any setting. Graf 5, sentence 2: "fundamental security features (full field encryption, randomization through IVs) were disabled" -> Randomized encryption isn't a feature, it's a fundamental property of a cryptographic construction. Graf 6, sentence 1: "currently in the process of obtaining our FIPS 140-2 certification" -> FIPS 140-2 doesn't involve a rigorous analysis of cryptographic primitives; the crypto-specific components focus on use of NIST-approved ciphers and block modes, but do not assure that those primitives are used securely. To illustrate that point: every vulnerable version of SSL3 and TLS1.0 and TLS1.1 has had a FIPS-compliant implementation somewhere. They should just be honest about their desire to suppress the use of their copyrighted IP in critiques of their product. They're in a competitive space, they're a small company, hard to manage their online reputation and build product, &c. The Reddit/HN/Stack Overflow scene wouldn't like that response, but it's better than this one, which actually creates more questions about their product capabilities.
- TillE 13y ago> their desire to suppress the use of their copyrighted IP in critiques of their product Which is a textbook case of fair use. They may want to do that, but legally, they almost certainly can't.
- zapdrive 13y agoAn example needs to be set. They should be sued for issuing a DMCA notice in bad faith.
- rdl 13y agoThis is a good example of bad legal/PR turning a company from a fairly well respected new security company to a joke. Tokenization, which CipherCloud does, could actually be done fairly securely if you had a decent amount of local storage. They IIRC use a FIPS HSM for local key storage in their local appliance (I talked to one of their founders as a security event a year or two ago and was initially suspicious of their claims, but it seemed adequate for certain use cases based on how they were using it -- maybe things have changed). It's fundamentally not too different from when Stripe gives you a user key vs. PCI information. Basically, if you can correctly identify certain fields as sensitive and others as not, and force all your traffic through a proxy, you could do totally unrelated random tokens in fields, and then do search locally on the appliance, rather than on the untrusted service. E.g. if you wanted to use Salesforce, but keep customer addresses secret (because they were super-confidential government sites or meth labs or something), you could still put names in Salesforce and do everything else, but just put a random string in for addresses; do address searches on the proxy, either going from single record to address or maybe even "give me all the records in Missouri". There is no magic here. Someone could do an open source implementation for any specific site (via scraping or a public API) easily. The difficulty is doing it for many sites, and keeping it updated, supporting it, and selling it to fortune 500. I don't know if they've been pushed to do stupid stuff, or if they just have horrible marketing/PR now (which is weird since they raised a fuckton of VC), or what.
- wyck 13y agoIt sounds like they don't have anyone with actual PR experience. The standpoint they are taking is very old school and stems from an angry reaction. If instead they had entered the discussion with a sliver of respect and honesty it would have been great. Instead many people have been introduced to them via a negative and untrustworthy atmosphere, this has certainly tarnished their reputation. Despite what they say not all exposure is good exposure.
- rdl 13y agoPeople should learn from their example. I'm not sure if it's that they have no PR experience in the company, or just don't consider StackExchange/HN/Reddit to be worthy of a serious effort. IMO, this is the kind of thing founders should handle personally once it happens. Maybe guided by a PR person or an investor, but a founder giving an adequate response gets graded on a curve, and is thus a lot more effective than a completely polished PR/marketing person.
- lwf 13y agolooking at the page in Google's cache, it looks like they have a bunch of spam on their site :) https://webcache.googleusercontent.com/search?q=cache%3Ablog.ciphercloud.com%2Fresponding-to-the-myths-about-cipherclouds-encryption-technology%2F&aq=f&oq=cache%3Ablog.ciphercloud.com%2Fresponding-to-the-myths-about-cipherclouds-encryption-technology%2F&aqs=chrome.0.57j58.845j0&sourceid=chrome&ie=UTF-8 https://webcache.googleusercontent.com/search?q=cache%3Ablog... "A couple of recent discussions in a few board threads contributed to by our competitors have questioned CipherCloud’s small online payday loans. same day payday loans. easy online payday loan. direct lender payday loans online. approach to delivering cloud information protection."
- dchest 13y agoLooks like your usual WordPress malware.
- zapdrive 13y agoHere is a link to the DMCA notice, in case anyone cares. Its not just a DMCA notice, it contains claims against slander and defamation too. http://www.pdf-archive.com/2013/04/20/notice130419/ http://www.pdf-archive.com/2013/04/20/notice130419/
- signifiers 13y ago“The statement is patently false. Sid implies that what was perceived from a public demo is CipherCloud's product offering.” http://www.pdf-archive.com/2013/04/20/notice130419/preview/page/3/ http://www.pdf-archive.com/2013/04/20/notice130419/preview/p...
- danbruc 13y ago»CipherCloud's product is NOT deterministic.« No, really, it is not. They say it three times. Who has not at least once dreamed of having your data processed by a non-deterministic system?
- edmccard 13y agoI think they are claiming that they are not using deterministic encrpytion[1], which can be used to allow searches of encrypted data, not that their software is "non-deterministic". [1] http://en.wikipedia.org/wiki/Deterministic_encryption http://en.wikipedia.org/wiki/Deterministic_encryption EDIT: Or maybe you know that and I missed the joke.
- danbruc 13y agoI know the difference between probabilistic and deterministic encryption but I did not think of it at the time I read the PDF and posted the comment. »[Our] product is NOT deterministic.« instead of »Our encryption algorithm is not deterministic.« tricked my brain into visualizing their software as a random number generator. So it is good that you point that out, I misinterpreted their statement.
- danbruc 13y agoI see no way this could ever work the way they want and still be secure. They have two conflicting requirements - strongly encrypting the data and not breaking the functionality of third party applications operating on this data, that is making the encryption transparent to a (sub)set of operations (not under their control). It is feasible to strongly encrypt all data but you have to make sure that you do not accidentally implement ECB mode or something similar when using a common block cipher like AES. So you definitely want a unique IV for every piece of data you encrypt. But now you have also broken all server-side functionality because (almost) no useful operation will produce the expected result when operating on encrypted data. Client-side functionality is no problem because it only sees decrypted data. Therefore they (have to) make compromises. Actually the user has to make the compromise - keep some data unencrypted or lose the server-side functionality. This is most prominent in the demos with numeric data that needs to be aggregated, averaged and what not. Actually it would be not to easy to encrypt this numeric data because you have to preserve the format including limits and disallowed values or otherwise the server would reject some values. What about the infamous text fields? They are probably the easiest to encrypt but you still have to be careful not to break validation rules, for example by making the encrypted text much longer or making an e-mail regular upset (but I bet most applications perform only client-side validation). But this again makes the third-parts application a lot less useful because you lost the ability to search in your textual data. The problem to solve is the following one (with some minor details ignored). text.contains(searchText) == encrypt(text).contains(doSomething(searchText)) I - not being a cryptography expert - can not think of a way to get this working without leaking information and CipherCloud's solution as discussed on Stack Exchange definitively leaks a lot of information. This is really a very tough problem. (Probably) not even homomorphic encryption would help because you have no control over the comparison method - it is plain old substring search, maybe case insensitive and that's it. It is solvable using private information retrieval in the relaxed case when you have control over the comparison operation but with substring search it is probably to hard (if you want to keep the cipher text length similar to the plain text length).
- darkarmani 13y ago> A couple of recent discussions in a few board threads contributed to by our competitors have questioned CipherCloud’s approach to ...DMCA takedown requests.
- pessimizer 13y ago"All of our customers, that I know of, have selected our solution as the recognized standard for cloud information protection after a thorough evaluation, testing, and scrutiny of our product’s design and implementation by their cryptographers and key management experts." If you had to guess, how many of CipherCloud's customers do you think keep cryptographers on staff?
- L0j1k 13y ago"We are terrible at putting out fires" is what I read here. And that's not a quality I want in a service provider...