Microsoft scans the inside of password-protected zip files on the cloud

jim584672

Thinks s/he gets paid by the post
Joined
Feb 4, 2014
Messages
3,099
Microsoft is scanning the inside of password-protected zip files for malware
If you think a password prevents scanning in the cloud, think again.
Dan Goodin - 5/15/2023, 8:15 PM

Microsoft cloud services are scanning for malware by peeking inside users’ zip files, even when they’re protected by a password, several users reported on Mastodon on Monday.

https://arstechnica.com/information...-of-password-protected-zip-files-for-malware/

--------------------------------------------------------
The cloud is a great way to back up important files off site.

If you want actual privacy use proper methods and software.

https://gnupg.org/download/

Use a proper password like: xCUQNHrRb1RKXV$rX3dl12@rNe4iAX8j for symmetric encryption.
Command line: gpg --output 'files.zip.gpg' --symmetric --cipher-algo AES256 'files.zip'
Never send a password in the clear.

Or exchange public keys with others for key exchange without a secure channel.
 
I don't store in the cloud.
 
A more dependable way is to use an AES-256 encryptor built into many archive programs when creating 7z files.
That's what I do. Not only does using 7z files allow for password protection of the files, but you can also select to encrypt file names so that a listing of the 7z file contents is not obtainable without the password.

I don't store in the cloud.
An even better suggestion if you are concerned about someone accessing the data.
 
Why does this not surprise me? :(

I don't store passwords in the cloud.
 
I don't store in the cloud.
Me neither. I see no value in it. Transfers are slow, many cloud vendors are not trustworthy, and even the large vendors are "down" from time to time. And then there is the security thing. Granted, storing periodic backup compilations on a hard drive kept in my gun safe is not as secure as having them off-site, but it is good enough for me.
 
If I want something safe, I encrypt it.

Simple password protection may only block an application from opening it.

As for the cloud, I enjoy the clouds passing by on a sunny day but I won't put sensitive data in them. :)
 
Back
Top Bottom