20 comments on “Is Using the Cloud Safe?”

  1. One thing I do is to check if a website allows a user name other than an email address. If it does, I make one up. I also check the password requirements for a site and max them out. Since I use LastPass, remembering them isn’t a problem. If two factor authentication is available, I use it.
    Bottom line is anything I can do to make it harder to guess, I do it. I keep regular backups, so I am not concerned about data loss.
    One other thing for US readers. Equifax, Transunion, Experian, and, another credit reporting company, Innovis, all allow individuals to sign on to their services and to lock their credit reports. Of the four, Experian charges $4.99 a month, the others are free. Users can unlock their files when necessary and then lock them again. You can also request a PIN from the IRS that is needed when filing a tax return. You will receive a new PIN each year that must be entered on your return when filing.

    Reply
    • In 2018 there was a law passed (in the U.S.) that made all credit freezes free. They should be free at all the credit agencies. I don’t know if you’re making a distinction between a “lock” and “freeze”, but the term “lock” is used by Experian as a part of their paid security services. A credit freeze should never have a monthly charge.

      Reply
      • A “lock” gives you control of your credit report without having to contact the credit reporting agency and takes no time to unlock or lock it.
        Essentially a lock and a freeze are the same. I went back to Experian and I’m paying a little extra for additional services. To just do the lock wouldn’t cost anything.
        My main point is that is another way to protect yourself in the event of a data breach. 5 years ago, I had someone attempt to file my Federal tax return. The IRS and I both agreed that it was a foreign actor as they filed the return on December 31st for that tax year, which prompted a letter from the IRS. So, I know my data is out “there” somewhere, already. I’ve taken as much action as I can to make it useless to whoever might have it.

        Reply
  2. To me the cloud is simply a marketing term for the Internet. I have always believed that one should never consider the Internet as private, whether it be email or online storage. Someone somewhere has access to whatever you are doing on the net. I would never backup my files to the Internet unless I considered them public information.

    Reply
  3. Aside from all of the above concerns, my reason for not using cloud storage is simply that it slows down any system. Unless you are using a top of the line speed machine you are placing an extra load on your PC. If your machine is old or has weak hardware you will be shooting yourself in the foot as far as performance goes.

    Reply
    • I have 3 different cloud sync programs running on my computer and I haven’t noticed any lags. Any slowdowns would be due to a slow Internet connection and has little to do with the speed of the computer. Bandwidth is only significantly affected when files are being uploaded and downloaded so most of the time, just being logged into a cloud syncing site in itself has little effect on speed.

      Reply
  4. Is “The Cloud” Safe?

    Yes! Of course it is! It’s only silly ol’ us, & the way we sometimes (mis)use “The Cloud”, that can render it unsafe.

    “That’s why ‘The Cloud’ is dangerous.”

    Slightly reworded, I’ll actually agree with that: “That’s why The Cloud can be dangerous.”

    So, take heed! And don’t be dumb when using “The Cloud”! (It’s not very “stupid-friendly,” I’m afraid.)

    Reply
    • Driving a car is dangerous; crossing the street is dangerous. We do many things that are dangerous several times every day. We take precautions by using seatbelts, installing airbags, crossing at crosswalks and still looking for cars that might run a red light, etc. It’s the same with using the cloud. Use strong password to log in to the cloud and encrypt all your files you upload to the cloud. And use a password manager to keep track of your passwords. You can even store your encryption passwords in the password manager, so you only have to remember one password.

      Reply
  5. My dislike of what is called “the cloud” today, aside from my own perceived security issues, is the loss of “purchasing power”. What I mean by that is consumers are losing the ability to buy many useful things. I like to buy my cars and other large ticket items if I can afford to, rather than leasing. OK, I’m a control freak. My accounting software still does fine for me and it’s a 2000 version. I have been very happy with Windows 7, despite having another machine with Windows 10 on it. Eventually I will be forced to move to the other machine, but I’m fighting it. Using the cloud for applications just seems like a way that big software companies can pretend they’re selling you something, when it’s really only a short-term license. If they owned my accounting software, and decided it was time for me to upgrade, there would be an implied “or else” in the deal. They could, and probably would, stop me from using that application, as it was on a short expiration license.
    Maybe I’m an anachronism, but I like to own what I can own, and oft times today’s software companies are trying to stop that. JMHO. Thanks for the great info, askleo.com.

    Reply
  6. The reason the Cloud was used to market is that you are using somebodies else’s computer for storage. Yes, just like your email is stored on their computers, any documents you store online for access by multiple computers is stored on some companies computer. The difference is that there should be even more security over documents stored, than emails stored.
    Encryption is fine if you are the only one to access that document but becomes a real pain when the document is shared across the company. I have several spreadsheets on the cloud that I have password protected, but I would hate to hand access to somebody else with my password for that spreadsheet.
    You should keep a copy of the document/spreadsheet on your computer and back it up as changes are made to the document/spreadsheet in the cloud.
    The greatest danger to documents on the cloud is from the employees working for the company supplying the storage you are using. Much easier to hack from inside a company than it is from outside. This means that anything you do will not help since they not only have access to the documents stored but also your login data. This is normally how you get massive breaches of the cloud. This is where encryption of your documents and spreadsheets might help, as the cloud company will not have the encryption stored on your computer.
    I would agree with you that you should never use your password/passphrase that you use for the cloud for anything else. Evaluate what you have stored on the cloud. Does it really have to be there? If you only access it from the same computer and never share it, maybe it does not need to be on the cloud.

    Reply
  7. The cloud (i.e., servers and data-storage systems elsewhere, to include in Russia and China) is safe. Or so Leo asserts. I disagree.

    Leo and I are of different generations. I’m a math/engineering science BS/MS/Dissertation-short-of-a-PhD octogenarian, one or two generations ahead of Leo. A FORTRAN, put a-person-on-the-moon using a 2K/36K memory processor, kind-of-guy.

    Everything is safe … until it isn’t. And recently Leo posted a blog telling his readers to abandon LastPass, a “secure” password manager (https://askleo.com/lastpass-breach-2022-my-recommendation/). In his estimate it was no longer trustworthy. His recommendation on the latest LastPass security breach? “It’s time to move on. The questions are, to what and how quickly?”

    So how do we find out about compromises? Often second-hand and long after the fact. When it may be too late. And how do we know it’s too late? We don’t. We could become a victim long after a breach. The mumbo-jumbo, geeky explanations often released by the violated entity often tell us little to nothing.

    So when using internet or cloud-based services Leo suggests that we protect ourselves. I agree wholeheartedly. But unfortunately most of us do not have the time, level of expertise, and knowledge that Leo has to be comfortable in adequately protecting ourselves. (But I do appreciate that Leo is indeed trying to educate us!)

    The best advice whenever using any online or cloud-based service? Use lengthy passwords (a minimum of 16 random letters, numbers, and characters, both upper and lower case) and two-factor-authentication. Encrypt if possible. Then hope that the service provider has its security act together. And maybe, like me, minimize the use of these services unless there’s no reasonable alternative.

    My current employer – I‘m still employed supporting a DOD/Space Force contract – does not allow us to use cloud services to store work-related, unclassified-but-sensitive information when logged onto its system/network. Rather, we use encrypted, password-protected external hard drives. Understandably so.

    Reply
    • I don’t trust the cloud either, but it’s not very difficult to encrypt the files you upload to the cloud. As I said in a previous comment, encryption can be as simple as using 7Zip to encrypt files. Yes, it’s a couple of extras clicks, but it’s something anybody can do.
      I just ran a test. I encrypted a 250 MB folder with a 30-character password. It took me about half a minute to encrypt it. It would take a similar amount of work to decrypt the folder. You can keep an unencrypted copy of that password somewhere safely on your computer or in a notebook or somewhere in your home. If you want a memorable password, you can use something like “Thequickbr0wnf0xjumped0verthelazylapt0p?” Memorable, but uncrackable.

      Reply
  8. I think the whole point here isn’t the technical part of the cloud. The question is WHO is the cloud? Is it Microsoft, AT&T, Samsung, Google etc. or the government? What do THEY do with all the personal information they have on hand from every internet user around the world? I think they’ve pushed us all into a corner where we can only say YES and AMEN to everything how THEY treat us as transparent people. Eat or die!

    Reply
    • This is an argument for encryption. Email is a cloud service. Unencrypted emails are as private as postcards. Unfortunately, email encryption is difficult. I’ve done it, but it’s not practical for the average person at this point. You’d have to exchange public keys beforehand. Encrypting files you keep on the cloud is easy. It can be as simple as .zip encryption or as sophisticated as using Cryptomator of VeraCrypt which are not too difficult for the average user. As the saying goes, “Trust but verify.” When it comes to the cloud, “Trust but encrypt.”

      Reply
  9. I misspelt my cloud email address How can I change this to my correct email address to match my email I have had for 20 years?

    Reply
    • It’s impossible to say without knowing which cloud service. It might not even be possible if they require a confirmation sent to your registered email. If that’s the case, I’d open an email with the mistaken address so that I would have a recovery email address.

      Reply

Leave a reply:

Before commenting please:

  • Read the article.
  • Comment on the article.
  • No personal information.
  • No spam.

Comments violating those rules will be removed. Comments that don't add value will be removed, including off-topic or content-free comments, or comments that look even a little bit like spam. All comments containing links and certain keywords will be moderated before publication.

I want comments to be valuable for everyone, including those who come later and take the time to read.