What is Zero-Knowledge Encryption?

Imagine you were Julius Caesar, standing at the head of your army. Are you ready to lead them across the vast lands of Gaul? Sure you are, but something’s bothering you… the threat of espionage. You’re worried that the messages you send back to Rome may fall in the hands of the enemy. What you need is a way to protect your plans and ensure that if the wrong hands get hold of your correspondence, it’ll be rendered useless. So, one day, in the midst of military strategy and campfires, you devise a clever solution: a simple yet ingenious cipher.

You take the alphabet you know so well and shift each letter by a few places. For example, the letter “A” becomes “D,” “B” becomes “E,” and so on. Thus, a message like “RUN”, would be encrypted as “UXQ”. You call it a cipher, and it becomes your secret weapon.

The beauty of your Caesar cipher is in its simplicity. Someone who knows the key can easily decrypt the message. However, anyone without it will be left puzzled. You didn’t know it then, but this rather simple strategy of yours would lay the foundation for centuries of cryptographic innovation.

Cryptography may sound complicated, but put simply, it’s the process of converting data into a special code that prevents unauthorised access to the information. And the only way for someone to decipher the coded message is with the encryption key.

The question that follows is: Who has knowledge of that key?

Zero-Knowledge Encryption

The first rule of zero-knowledge encryption is that ONLY YOU hold the encryption key to your data. That is, you’re the only one who can decrypt your files.

Moreover, only the encrypted version of your data is stored on the cloud storage server, so neither the service provider, nor a potential attacker, even if they gain access to your account password, would be able to access your files. In fact, they can’t even tell whether your files are photos, or documents.

So, how exactly does that work?

In a zero-knowledge setup, the cloud storage provider encrypts your data with an AES-256-bit symmetric encryption and decrypts it solely on your device. Imagine it like this, complex mathematical algorithms wrap your files in mystery, before they reach the cloud. If you come across the term a client-side encryption, well, that’s what it means.

And when your data is in transit (being uploaded, downloaded, or synced across multiple devices), it remains encrypted and safeguarded by Transport Layer Security (TLS).

pCloud Special

We’ve designed our zero-knowledge setup to be as user-friendly as possible. Once you enable our Encryption feature, you add a Crypto folder to your account. This gives you the freedom to have both server-side encrypted, and client-side encrypted files.

Why you might want both?

Well, because the client-side encrypted files are not instantly manageable. With pCloud you can choose which files to keep secretly locked, veiled in mystery, and which ones to remain unchanged.

You can see and access your client-side encrypted files in your pCloud Drive, only after you enter your encryption password (Crypto Pass) to unlock them. Once you click the Lock button, they will immediately become invisivble again.

Pros & Cons

Because it’s impossible to lose, use, or abuse data you don’t possess, zero-knowledge encryption replaces trust-based promises with mathematical assurances. This means users don’t need to rely on the integrity of the company to protect their data. Instead, their data is secure due to the methods that are used. And with pCloud one doesn’t have to sacrifice convenience over security, because our cloud solution offers the possibility of having mixed content, both zero-knowledge encrypted, and server-side encrypted.

No need to think twice, then! Go ahead and ADD ENCRYPTION NOW!

Spread the word: