Several cloud service providers promise users complete privacy and protection from surveillance through the adoption of zero-knowledge security policies.
Zero-knowledge cloud work by storing data in encrypted form and providing users with unique keys to decrypt it, to which providers do not have access.
However, a recent study by Johns Hopkins University calls into question the security of these specific security policies:
Experts found that if data is shared via a cloud service, these keys could be vulnerable to attacks, allowing providers to gain access to customer data.
Several cloud service providers that promise zero-knowledge protection – such as Spider Oak, Wuala and Tresorit – use a method where data is encrypted when stored in the cloud and decrypted only when downloaded by a user. This model is secure. But the researchers warn that if data is shared in the cloud, meaning it is sent through the service without the user downloading it to their system, then the providers have the opportunity to see it.
For more information you can see the full report here.

