Public Links to encrypted backup in cloud
My understanding is that if I create a password-protected backup and store it to the Acronis Cloud, then the backup is encrypted AES-256 on the local machine and passed securely to the Acronis server, and that no information is also passed to the server that would allow decryption of the backup after it leaves the local machine.
However, the Cloud browser has the option of creating a Public Link. It appears from my testing that creating this public link and passing it to a third party will allow the third party to browse a decrypted version of the backup on the server. Can someone explain how this is possible if the backup on the server is really encrypted?
In fact, now that I think about it, I don't even understand how the Cloud browser can work if the backup is really encrypted on the server since it shows an unencrypted view of the file structure of the backup in a browser window.
Skip


- Anmelden, um Kommentare verfassen zu können

Thanks, Steve.
I'm just trying to understand how secure Acronis Cloud may be. I do not see how it is possible to create a feature such as a public link unless Acronis can decrypt the file on its server. Perhaps unencrypted versions are also stored on the server. I don't understand why Acronis does not publish fully the details of how cloud encryption works, and this makes me suspicious that there are holes in the process. My concern is about maintaining the security of my data since I would expect the Acronis Cloud to be a prime hacking target.
Skip
- Anmelden, um Kommentare verfassen zu können

Skip, the best advice I can offer here is for you to open a Support Case with Acronis to ask for further assurances about the security of your data stored in the Acronis Cloud / servers.
- Anmelden, um Kommentare verfassen zu können

Hi,
I noticed the same thing, as George Foster did. This looks like a serious security risk. I have the newest ATI version 2019, build 14110.
Is there any way to disable at all linking feature for my account / backup? Also... I'm also wondering... how can one access linked files if they are encrypted, without typing in private key, hmm??
- Anmelden, um Kommentare verfassen zu können

Adam, please see my earlier comments on this topic.
Public links require the user to provide the encryption password when they are being created, so the ultimate control here is with that user.
If you do not need or want to use public links, then there is no security exposure unless you still go ahead and create such links.
If you want to share specific data via the Acronis Cloud, then make a separate backup to upload that data, with or without encryption according to how secure it needs to be, then create a public link only to that data or a subset of it.
Further than the above, if you are really concerned then you should open a Support Case directly with Acronis to explore any security concerns about these public links to your Cloud data.
- Anmelden, um Kommentare verfassen zu können

Thanks, Steve. I raised a Support ticket. Documentation could be a little more detailed on this manner, to avoid asking such questions by users over and over again.
- Anmelden, um Kommentare verfassen zu können

Hello Everyone,
just wanted to add that the shared links are password-protected now
- Anmelden, um Kommentare verfassen zu können