Research exchange

PhDSciNet Interview 25: Are Cloud Drives Safe?

Chilled Foam discusses cloud backups, attack chains, defensive layers, and network keys. The interview is preserved with corrections to key explanations of cryptography, certificates, and HTTPS.

PhDSciNet Interview 25: Are Cloud Drives Safe?

Historical interview: The following preserves the research experiences and personal views expressed in the original manuscript.

PhDSciNet Interview Series

Are Cloud Drives Safe?

Last time, we discussed the feeling that our online environment is not particularly safe. Let us continue by talking about network defense and attack!

Are Alipay and WeChat Pay safe?

Chilled Foam: I think mainstream payment platforms generally invest more in security teams and maintenance, but size does not guarantee absolute safety. PCI DSS, mentioned here, is an industry security standard for protecting payment-card account data, not a universal online-payment communication protocol. A platform's actual standards and assessments need to be checked against the relevant business and evidence; they cannot be established from this interview alone.

Figure 1: Mobile payment
Figure 1: Mobile payment

Are cloud drives safe?

Chilled Foam: Personally, I am cautious about putting sensitive material in a cloud drive. Photographs of identity documents or bank cards may automatically sync to the cloud alongside ordinary pictures, so access permissions and sharing settings need attention. [Editorial correction: Removed the source's unverified claim that a partly masked cloud-drive platform had been decrypted and everything in it could be seen. The available material does not support that conclusion about the platform.]

Not hearing about a platform's data leak in an interview does not mean it is risk-free. Hearing an unverified rumor does not establish that it was compromised either. Judgments should be based on specific incidents, permissions, and data-protection measures.

I also use cloud drives regularly to share files with my supervisor. My advice is that cloud services can be used, but important information should have an appropriate separate backup, rather than relying on one cloud copy alone. Whether lost data can be recovered depends on backups, version history, and the service; it is incorrect to say that all lost cloud data is unrecoverable.

[My own unfortunate experience]

Chilled Foam: During my PhD, one task was to construct attack sequences to test whether my defenses worked. I could not try them elsewhere, so I used my own platform—and ended up hacking myself. Perhaps I had configured a port incorrectly: an internal loop locked me out so completely that I could not undo it. I was furious. I had to reinstall the system, so the absence of a backup can be disastrous.

Unless information is classified, what we normally encounter is generally not sent outside public networks. Highly classified material would not usually travel over them, while much of the information on public networks is not especially valuable. We need to balance a comfortable user experience with vigilance about security, rather than worry excessively.

How are networks attacked?

Chilled Foam: We can summarize the process through an “attack chain.” The original interview divided it into several stages: collecting information and identifying targets, finding vulnerabilities, preparing tools and strategies, reaching the target system, obtaining privileges, carrying out malicious activities, and concealing traces or withdrawing. This is a simplified way of understanding the process, not a universal seven-step model followed in strict order by every attack.

The first step is gathering information and identifying a target. Many tools are now available to collect information, including about control centers in large factories or personal laptops: personal details, company information, or configuration files, for example.

After identifying a target, the next stage generally involves analyzing that information to find vulnerabilities or weak points. If you enter personal information on a website or upload personal identification, for example, an attacker might analyze and classify it and use it to plan attack routes and tools.

When executing an attack, the tools first have to reach the target, such as your computer. This might happen through email, a compromised website, or a USB drive. Exploitation can then begin, potentially providing entry to a server and access to password files, certificates, or personal information. At that point, the attacker has entered the target system.

Once inside, an attacker often first tries to escalate privileges, moving from guest access to higher administrative rights and access to sensitive data. With those rights, they may install a control program to remain in the computer for a long time. We commonly call that installing a Trojan.

That establishes a persistent connection between the attacker and the target computer. The attacker can continue extracting data, inserting false information, deleting or adding material, or modifying data.

Beyond causing damage or achieving other malicious goals, another aim is to conceal or remove evidence so that later investigations cannot trace the attack back to its source. Attackers may extract data while also removing evidence.

By that point, the attack is largely complete. The final step is to remove traces and withdraw without being noticed.

Figure 2: A network attack
Figure 2: A network attack

How long does an attack take?

Chilled Foam: It depends on the target. Many attacks are now relatively concealed; highly visible attacks designed to show off have become less common. Most are quiet and hidden, including what we call advanced persistent attacks. In a large system, an attacker may remain unnoticed for half a year, or even one or two years. For individuals, things can happen much faster: at the quickest, in seconds, or, at the slowest, over years.

What defensive strategies are available?

Chilled Foam: We analyze defense against the stages described above. For example, attackers identify targets and look for attack surfaces. Potential points of attack include things exposed externally: IP addresses, open ports, USB or SD interfaces, network and Bluetooth connections, MAC addresses, and the webpages we visit. We should reduce unnecessary exposure where possible.

Attackers want to collect as much information as possible, so we need to be careful about exposing sensitive data. There is an important distinction here: directly exposing passwords on webpages or in files is different from securely storing them in a reliable browser or password manager. A password manager can help each account use a different strong password and should not automatically be compared with hanging a key on the door.

They then seek vulnerabilities, and we can also detect and defend against them. Firewalls, anomaly monitoring, and security software can help discover or limit some attacks. Encryption mainly protects confidentiality; integrity generally also needs authentication mechanisms. Encryption does not automatically detect every anomaly. Businesses also apply least privilege, granting access according to work needs and separating duties where appropriate.

In a defensive architecture, we generally establish defense in depth. We classify data according to importance and apply different protections to different levels. Businesses, and especially some government departments, may hold highly classified information, so they configure protections for each data category and apply controls in layers.

Networks have many layers, from the physical layer at the bottom to the application layer at the top, with corresponding detection and defensive measures at each level. Within one layer, there can also be several controls, such as firewalls and alarms. Boundary protections and encryption can be included as part of a diverse set of controls at multiple points.

Figure 3: Defending network security
Figure 3: Defending network security

We often see the term “network key.” What does it mean?

Chilled Foam: There are many kinds of keys, just as there are many kinds of cryptographic algorithms.

For example, data can be in transit, in use, or in storage. Stored data can often be protected with symmetric encryption, which uses the corresponding secret key for encryption and decryption and is generally efficient. Whether and how to use it depends on the data's state, threats, and key management. The idea that a database is “one-way data” is not an explanation of encryption.

Sensitive applications such as banking combine different cryptographic techniques. Asymmetric methods use related public and private keys for authentication, signatures, or establishing keys; real network connections often then use symmetric encryption to protect transmitted data. This is not simply a matter of each side using a separate algorithm, nor can these techniques alone guarantee that a bank will not cheat or completely eliminate man-in-the-middle attacks.

A hash function, called a “Haishi algorithm” in the source, maps its input to a digest. It is not encryption that “only encrypts and never decrypts,” and a digest alone does not prove the sender's identity. Authentication may also require digital signatures, message-authentication codes, or other mechanisms. Quantum cryptographic technologies are a different research direction; this interview alone does not establish that ordinary 5G communications already use quantum encryption.

Figure 4: Network keys
Figure 4: Network keys

What does a certificate mean?

Chilled Foam: A digital certificate links identity information or a domain name with a public key and other information, and can support authentication in a connection. HTTP itself does not provide TLS transport protection, but that does not mean a site's server-side source code is completely open, nor does the protocol prefix alone tell you whether the site has other safeguards.

When entering payment or sensitive information, check the correct domain and a protected connection. HTTPS uses TLS to protect HTTP communication; the source's “TRS” should be TLS, while SSL is an earlier related protocol. Typically, the browser verifies the server's certificate and establishes an encrypted connection. The certificate does not first validate the user's username and password. HTTPS helps protect data from being read or altered in transit, but does not guarantee reliable content, a vulnerability-free platform, or protection against every scam.

Fantuan: Is it a little like having a passport that proves who you are before you can travel?

Chilled Foam: A certificate can be understood as part of the browser checking the server's identity. This “passport” mainly authenticates the server, rather than proving every visitor's personal identity. HTTP normally lacks TLS transport protection, while HTTPS protects communication between the browser and server. That protection has limits and does not mean the whole website or endpoint is absolutely safe.

How do you establish a defensive system?

Chilled Foam: First, we consider defense in depth. Architecturally, it is layered, classifies data, and uses diverse controls at multiple points. Technically, the defensive system also integrates its components. First, it tries to block an attack; if blocking fails, it can still detect it. If detection fails too, defenses inside the system may resist the attack. If those defenses also fail, incident response can limit further damage. Overall, it is a closed-loop defensive system.

A defensive system analyzes abnormal behavior in a network. We may combine information from several domains and sources. Big-data methods, deep learning, or artificial intelligence are often used to analyze security conditions, identify potential threats, and strengthen systems.

Zero-trust architecture is also often discussed in management: someone or a device should not automatically receive unrestricted access merely because it was considered trustworthy before. Identity, devices, context, and access policies require verification and ongoing assessment. “Verifying everything repeatedly” should not be interpreted as requiring users to re-enter multifactor credentials for every individual action.

Endpoints and attack surfaces need controls on entry and exit. There is also authentication, anticipation of threats, and different permission management for different users. Network layers can be divided into zones, with different management approaches and verification mechanisms for people, technologies, and data.

Normal operation requires security controls and reasonable, compliant management. Although we have discussed many methods, defense is fundamentally dynamic. We need a responsive mechanism that monitors and defends in real time while updating strategies.

These principles are abstract. At the level of individual use, security awareness is an important foundation, but cannot guarantee safety by itself or establish that security necessarily improves by “more than half.” Appropriate technical measures and maintenance are also needed.

Are there bottleneck technologies or promising frontier areas in the overall defensive process?

Chilled Foam: At the time of the original interview, cloud security was widely discussed because much work and business activity took place through the cloud. 5G, cloud services, and zero-trust architecture were also often discussed together in related security research and deployment, but they are not the same technology.

Quantum encryption and other new cryptographic algorithms are also being developed. Another popular approach is agile security development, in which security facilities and the design process advance together.

From a data-processing perspective, machine learning and artificial intelligence are frontier technologies. Integrating them into security is a popular and much-needed direction.

Figure 5: Cloud security
Figure 5: Cloud security

Where does China stand in cybersecurity research?

Chilled Foam: In terms of security, China is still at an early stage and started relatively late. But the country gives it substantial attention: cybersecurity is specifically included in the 14th Five-Year Plan, and there is a cybersecurity week every year. Although China started late, its strengths include what is currently the world's largest data resource. Big data and 5G are very advanced, as are applications of artificial intelligence in China.

What would you like to say about cybersecurity? Feel free to leave a comment!

Science presenter: Chilled Foam (冰镇泡沫)

Editor: Honey Peach Oolong

Interviewers: Fantuan and Calorie

Audio recording: Calorie

Revised on 2026-10-10: Distinguished PCI DSS, symmetric and asymmetric cryptography, hashing, and TLS/HTTPS certificates; corrected statements about password managers, zero trust, and encryption detecting anomalies; removed an unverified claim that a particular cloud drive had been compromised; and retained the historical interview context of cloud backups and defense processes.

Supplementary references

Sources and editorial history

Restored from a complete historical article exported from the PhDSciNet Official Account.

Editorial revision: Revised on 2026-10-10: Distinguished PCI DSS, symmetric and asymmetric cryptography, hashing, and TLS/HTTPS certificates; corrected statements about password managers, zero trust, and encryption detecting anomalies; removed an unverified claim that a particular cloud drive had been compromised; and retained the historical interview context of cloud backups and defense processes.

What would you like to explore?