The Convenience and Risks of Cloud Storage
Google Drive, Dropbox, iCloud, OneDrive - cloud storage is widely used by individuals and businesses alike for the convenience of reaching your files from any device. Services such as cloud gaming, which hand the processing itself over to the cloud, are spreading as well. But the act of keeping your data on someone else's servers rather than in your own hands carries risks of its own.
When you think about cloud storage security, understanding the balance between convenience and safety is the starting point.
Risks Lurking in Cloud Storage
Account Takeover
Access to cloud storage is usually protected by nothing more than an email address and a password.
If that password leaks, every file you have stored is exposed. Credentials that surface through a data breach are reused against cloud accounts often enough that it can hardly be called rare.
Misconfigured Sharing
Leaving a confidential file on the "anyone with the link can access" setting is a mistake that happens constantly. Once such a link travels further than intended, the file is open to anyone who receives it.
Risks on the Provider's Side
The provider itself can come under attack. And where the provider's own staff can reach your data, the possibility of insider misuse exists too.
What decides how far such an incident reaches is who holds the encryption keys. With most services the provider manages the keys, so if an attacker seizes privileges on the management platform, or internal privileges are abused, the contents of your files become readable even though they were encrypted at rest. Of the measures available to you as a user, the only one that works independently of anything that happens on the provider's side is encrypting your files with your own key before you upload them.
Legal Jurisdiction Issues
Depending on the country where the servers holding your data sit, that country's laws may allow the data to be disclosed.
A demand of this kind is directed at the company holding the data, not at you. If the provider manages the encryption keys, it can hand over the data in readable form; if you encrypted the files with your own key before storing them, all it can hand over is ciphertext. For data used in a business context, it is worth checking whether you can choose the region (country or area) where files are stored, and whether backups and replicas stay within that same region once you have chosen, so that the assumptions you relied on do not quietly collapse later.
How to Use Cloud Storage Safely
Strengthen Your Account Security
- Set a strong, unique password
- Always enable two-factor authentication
- Review your account activity log regularly
- Revoke third-party app integrations you no longer use
Manage Sharing Settings Properly
- Revisit the sharing settings on files and folders periodically
- Share with named users instead of "anyone with the link"
- Put an expiry date on shared links (where the service supports it)
- Turn off sharing promptly once it is no longer needed
Encrypt Important Files
Encrypting a file locally before you upload it keeps third parties, the provider included, from reading its contents. Tools such as Cryptomator and VeraCrypt are available for this.
Choose Services with End-to-End Encryption
Some cloud storage services offer end-to-end encryption (E2EE). With E2EE the data is encrypted on your own device, so not even the provider can read what is inside.
Cloud Storage as a Backup Strategy
Cloud storage is useful as a backup destination, but it should not be your only one. Follow the "3-2-1 rule" also discussed in ransomware protection and keep copies both in the cloud and locally, on an external drive for example. Bear in mind as well that deleting a file in the cloud does not guarantee that the data is wiped for good.
The other thing that is easy to overlook is what synchronization does for you automatically. When a file inside a synced folder is encrypted, corrupted, or deleted, that change is carried straight up to the cloud copy. Most services keep version history and a trash folder, and within the retention window you can roll back to an earlier state, but the retention window differs by service and by plan, and if you notice the damage late it can expire before you get there. Keeping one copy outside the sync scope is your insurance at this point.
Actions You Can Take
Using cloud storage safely rests on protecting the account with a strong password and two-factor authentication, revisiting sharing settings on a regular basis, and encrypting the files that matter. Enjoy the convenience, but stay conscious of the balance that keeps the risk down.
Check the security state of the connection you are on now with IP Check-san, and confirm that your access to cloud services is travelling over a safe route.
Related Glossary Terms
Frequently Asked Questions
Is it OK to store passwords in cloud storage?
Keeping passwords in a plain text file in the cloud is dangerous: if your cloud account is compromised, every password leaks at once. Use a password manager so they are stored encrypted.
Is my cloud storage data encrypted?
Major services (Google Drive, Dropbox, OneDrive) encrypt data in transit and at rest, but the provider holds the keys, so the provider itself can reach your files. If you want the data unreadable even to the provider, pick a service that supports end-to-end encryption (Tresorit, for example), or encrypt the files yourself before uploading with a tool such as Cryptomator.