By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Researchers Discover Severe Security Flaws in Major E2EE Cloud Storage Providers
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Researchers Discover Severe Security Flaws in Major E2EE Cloud Storage Providers
Tech News

Researchers Discover Severe Security Flaws in Major E2EE Cloud Storage Providers

By Viral Trending Content 5 Min Read
Share
SHARE

Oct 21, 2024Ravie LakshmananEncryption / Data Protection

Major E2EE Cloud Storage Providers

Cybersecurity researchers have discovered severe cryptographic issues in various end-to-end encrypted (E2EE) cloud storage platforms that could be exploited to leak sensitive data.

“The vulnerabilities range in severity: in many cases a malicious server can inject files, tamper with file data, and even gain direct access to plaintext,” ETH Zurich researchers Jonas Hofmann and Kien Tuong Truong said. “Remarkably, many of our attacks affect multiple providers in the same way, revealing common failure patterns in independent cryptographic designs.”

The identified weaknesses are the result of an analysis of five major providers such as Sync, pCloud, Icedrive, Seafile, and Tresorit. The devised attack techniques hinge on a malicious server that’s under an adversary’s control, which could then be used to target the service providers’ users.

Cybersecurity

A brief description of the flaws uncovered in the cloud storage systems is as follows –

  • Sync, in which a malicious server could be used to break the confidentiality of uploaded files, as well as injecting files and tampering with their content
  • pCloud, in which a malicious server could be used to break the confidentiality of uploaded files, as well as injecting files and tampering with their content
  • Seafile, in which a malicious server could be used to speed-up brute-forcing of user passwords, as well as injecting files and tampering with their content
  • Icedrive, in which a malicious server could be used to break the integrity of uploaded files, as well as injecting files and tampering with their content
  • Tresorit, in which a malicious server could be used to present non-authentic keys when sharing files and to tamper with some metadata in the storage
Cloud Storage Providers

These attacks fall into one of the 10 broad classes that violate confidentiality, target file data and metadata, and allow for injection of arbitrary files –

  • Lack of authentication of user key material (Sync and pCloud)
  • Use of unauthenticated public keys (Sync and Tresorit)
  • Encryption protocol downgrade (Seafile),
  • Link-sharing pitfalls (Sync)
  • Use of unauthenticated encryption modes such as CBC (Icedrive and Seafile)
  • Unauthenticated chunking of files (Seafile and pCloud)
  • Tampering with file names and location (Sync, pCloud, Seafile, and Icedrive)
  • Tampering with file metadata (impacts all five providers)
  • Injection of folders into a user’s storage by combining the metadata-editing attack and exploiting a quirk in the sharing mechanism (Sync)
  • Injection of rogue files into a user’s storage (pCloud)

“Not all of our attacks are sophisticated in nature, which means that they are within reach of attackers who are not necessarily skilled in cryptography. Indeed, our attacks are highly practical and can be carried out without significant resources,” the researchers said in an accompanying paper.

“Additionally, while some of these attacks are not novel from a cryptographic perspective, they emphasize that E2EE cloud storage as deployed in practice fails at a trivial level and often does not require more profound cryptanalysis to break.”

Cybersecurity

While Icedrive has opted not to address the identified issues following responsible disclosure in late April 2024, Sync, Seafile, and Tresorit have acknowledged the report. The Hacker News has reached out to each of them for further comment, and we will update the story if we hear back.

The findings come a little over six months after a group of academics from King’s College London and ETH Zurich detailed three distinct attacks against Nextcloud’s E2EE feature that could be abused to break confidentiality and integrity guarantees.

“The vulnerabilities make it trivial for a malicious Nextcloud server to access and manipulate users’ data,” the researchers said at the time, highlighting the need to treat all server actions and server-generated inputs as adversarial to address the problems.

Back in June 2022, ETH Zurich researchers also demonstrated a number of critical security issues in the MEGA cloud storage service that could be leveraged to break the confidentiality and integrity of user data.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

The Best Over-the-Counter Sleep Aids (2025), Tested and Reviewed

Feliz Navidad, Bodega Hampers reviewed

Can AI Solve Homelessness in Ireland?

How Anthropic’s Ralph Plugin Makes Claude Complete Coding Tasks

Best Streaming Service of the Year: Tech Advisor Awards 2025-26

TAGGED: Cloud security, cloud storage, Cryptography, Cyber Security, Cybersecurity, data protection, encryption, Internet
Share This Article
Facebook Twitter Copy Link
Previous Article Netflix hit a new high last month and keeps climbing! Should I buy the stock?
Next Article Sea of Thieves: Season 14 is Now Available
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

The Best Over-the-Counter Sleep Aids (2025), Tested and Reviewed
Tech News
US bank upgrades TeraWulf price target, offers bullish mining prediction
Crypto
Ethereum TVL Still Quietly Defining ETH’s Long-Term Price Stability And Ecosystem Growth – What To Know
Crypto
Feliz Navidad, Bodega Hampers reviewed
Tech News
MLB Top 10 Moments of 2025: From All-Star Game Swing-off to World Series Game 7
Sports
Hong Kong greets 2026 without fireworks after 161 killed in deadliest blaze in decades
World News
Foreigners dump record Indian bonds as weak rupee erodes returns
Business

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

The Best Over-the-Counter Sleep Aids (2025), Tested and Reviewed

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
The Best Over-the-Counter Sleep Aids (2025), Tested and Reviewed
December 31, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?