Zurich, October 21, 2024 – Researchers from ETH Zurich have discovered critical vulnerabilities in popular encrypted cloud storage platforms, potentially exposing sensitive user data to cyberattacks.
Cybersecurity experts from ETH Zurich have uncovered serious cryptographic vulnerabilities in several widely-used end-to-end encrypted (E2EE) cloud storage services. The flaws, which were found in Sync, pCloud, Icedrive, Seafile, and Tresorit, could allow malicious servers to tamper with files, inject rogue data, and even access plaintext content.
ETH Zurich researchers Jonas Hofmann and Kien Tuong Truong said,
The vulnerabilities range in severity: in many cases a malicious server can inject files, tamper with file data, and even gain direct access to plaintext. Remarkably, many of our attacks affect multiple providers in the same way, revealing common failure patterns in independent cryptographic designs.
The study highlights how adversaries can exploit these flaws by gaining control of a malicious server, which then targets unsuspecting users of these cloud platforms. Attacks ranged from file injections and tampering to accelerating password brute-force attempts.
Among the specific vulnerabilities identified:
- Sync and pCloud: Malicious servers can break file confidentiality and tamper with data.
- Seafile: Faster brute-force password attacks and file tampering are possible.
- Icedrive: Integrity of uploaded files can be compromised.
- Tresorit: Non-authentic keys can be presented when sharing files, along with metadata tampering.
Not all of our attacks are sophisticated in nature, which means they are within reach of attackers who are not necessarily skilled in cryptography,
While some of the flaws may not be groundbreaking in cryptography, they highlight the practical failures of E2EE cloud storage systems, leading to significant risks for users. Of the affected services, only Sync, Seafile, and Tresorit acknowledged the findings, while Icedrive has opted not to address the vulnerabilities following disclosure in April 2024.
This research serves as a stark reminder of the critical importance of robust encryption practices, as even supposedly secure platforms can fail at fundamental levels, putting users’ data at risk.
Other News At VPNRanks
- Everest Hackers Threaten CreaGen: Ransom Deadline Looms
- LinkedIn Hit with €310M Fine Over GDPR Privacy Violations
- Prompt Injection: AI’s New Cybersecurity Nightmare Unveiled
- Major Crackdown on Illegal Football Gambling Hits Hard
Hey, wait!
Stay informed on the latest privacy updates, cybersecurity insights, and internet freedom news by following VPNRanks news daily! As your primary resource for critical updates in online security, we ensure you’re always in the know. Make VPNRanks your go-to guide for safeguarding your digital life!