Encryptionis the process of encoding messages or information in such a way that it cannot be accessed without the key used to encode it. IDrive encrypts the files included in your backup set before the data is sent to your destination and it stores the data in encrypted format on your servers. Data encryption, combined with a secure private encryption key, prevents unauthorized access to your information.
IDrive backups are encoded with Advanced Encryption Standard (AES) 256-bit encryption algorithm. The Advanced Encryption Standard or AES is used by the U.S. government to protect classified information and is implemented in software and hardware throughout the world to encrypt sensitive data.
Default Encryption: When you install the IDrive application and choose 'Default Encryption', an encryption key is securely generated for your account. This key will be automatically used to encrypt all your data on transmission and storage.
Private Key Encryption: When you install the IDrive application and choose 'Private Key Encryption', you need to provide an encryption key of your choice. This key will be used to encrypt all the data on transmission and storage. Without this key, users cannot recover the data. This means, if the user loses the Private Key Encryption, then the data cannot be restored and our Technical Support cannot assist with recovery. It is thus recommended that the user archives this key safely to backup and restore data.
Yes. On resetting your private encryption key, all the data from your account will be permanently deleted. So, reset the private key only in case you have forgotten the key or want to upgrade security for your account.
Yes. Enabling the 'Private Key Encryption' option affects ALL of the computers on your account. Setting the Private Encryption Key on one computer sets the same Private Encryption Key for all your computers. You need to enter this Private Encryption Key on all the computers in your account.
There is absolutely no way for IDrive to recover your Private Encryption Key. If you forget or lose your Private Encryption Key, either you have to create a new account or need to opt for resetting your Private Encryption Key. However, on resetting your Private Encryption Key, all the data from your account will be permanently deleted as it cannot be decoded.
Your data resides on RAID-protected storage devices. In addition, we recommend that you keep a local backup of your data, as online backup should be a complementary solution to local backup and not be the ONLY solution for disaster recovery. To secure your local backup, IDrive supports encrypted local backups with Private Key Encryption option.
The information we collect from you is only for the purpose of providing you a backup service and communicating with you about the backup services we provide. For more information, read our complete Privacy Policy.
IDrive uses industry standard 256-bit AES encryption on transfer and storage. Data stored at our world-class data centers is encrypted using the encryption key (known only to you in case you set the private encryption key).
WARNING: IDrive does not store your private encryption key on its servers. It is recommended that you archive it safely to backup and restore your data. However, if you opt for the Default encryption key, you need not remember it.
Note: Resetting your account permanently deletes all your backed up files and folders. If you have opted for local backup, you will lose access to the locally backed up files, so delete them before resetting your account.
IDrive uses 256-bit AES encryption to transfer your Username and Password when you enter the sign in credentials. This ensures your details are secure during transfer since the information cannot be viewed by anyone as clear text.
These world-class facilities are custom designed with raised floors, HVAC temperature control systems with separate cooling zones, and seismically braced racks. They offer the widest range of physical security features, including state-of-the-art smoke detection and fire suppression systems, motion sensors, and 24/7 secured access, as well as video camera surveillance and security breach alarms.
The private encryption key is known only to you and no one else. Even the IDrive personnel do not have access to this key as it is not stored in the IDrive servers. You must try to recollect your private encryption key to retrieve your account data.
Both, default encryption and private encryption, use the 256-bit AES encryption to encrypt your data. Default encryption uses a system generated key, whereas for private encryption, a user-defined key is used.
IDrive does not store your private encryption key on its servers. It is recommended that you archive it safely to backup and restore your data. However, if you opt for the Default encryption key, you need not remember it.
Shellshock, also known as Bashdoor, is a family of security bugs existing in the widely used Bash Unix shell. To date, 6 CVE's regarding Shellshock have been filed, the first of which was disclosed on September 24, 2014. Many Internet daemons, such as web servers, use Bash to process certain commands. The Shellshock bug lets attackers cause vulnerable versions of Bash to execute arbitrary commands, allowing them to gain unauthorized access to a computer system. For more information, you may refer the Wikipedia article regarding Shellshock.
Our security team has verified that IDrive services are not affected by this security vulnerability. We nonetheless applied the necessary patches to all external and internal systems. We've also verified that our software is not susceptible to Shellshock. Our users are completely secure from this bug, and need not update or take other action to avoid it.
So while IDrive does not store the encryption key, a sample one-way encryption value is stored to validate future logins. Only the sample encrypted value is transmitted and at no time the key is transmitted to the servers. You can not deduce the key from encryption value as it is a one-way encryption.
Now, on the Web or the web based interface situation is slightly different. The process is exactly the same, except that the 'client' here is an 'intermediate processor' and not the desktop. The data is not decrypted on the actual servers that host the data, but on the 'intermediate processor' on the fly and then brought to the browser interface via SSL interface. The 'intermediate' processors are segregated from the servers that host the encrypted data. This is a slight compromise for ease of use. You can avoid accessing private key enabled accounts via the web to avoid this entire process that involves intermediate processors.
IDrive does not support private encryption for Google Workspace and Microsoft Office 365 backups. Your Google Workspace and Microsoft Office 365 backups are stored in top-notch data centers and secured with industry-standard 256-bit AES encryption on both transfer and storage.
Know more about data security for Microsoft Office 365 and Google Workspace backups.
IDrive assists users in achieving compliance to the benchmarks laid out under the Federal Information Processing Standards (FIPS) validation for cryptographic products/software used in the USA. IDrive uses FIPS approved encryption algorithms and adheres to physical security.
They also offer useful features like the ability to automatically backup your photos to the servers. More importantly from our perspective is that the mobile apps do support the use of your Private Encryption Key, despite what the documentation might say.
For this review, I installed the IDrive Full Client on my Windows 10 machine, and a Samsung S9+. The free plan requires you to submit your name, email address, and password, while the Personal / Business plan requires those items, plus a phone number, and full credit card information.
I signed up for the Free 5 GB plan for this review. This free plan requires you to submit your name, email address, and password. If I had signed up for the Personal / Business plan I would have been required to submit that information, plus a phone number, and full credit card information. Doing so also commits you to automatic yearly renewal of the subscription at the full price (instead of the discounted first year price). With any of the free or paid plans you must agree to receive email from IDrive about product updates.
If you want secure cloud storage, you need to select the Private encryption key option. The default approach uses an encryption key controlled by IDrive, which puts the security of your data in their hands. If you set a Private Encryption Key, your data gets encrypted with that key before it leaves your device. IDrive states that they have no access to this key so cannot decrypt your data if you select this option.
Note: If you have already installed IDrive using the default encryption, you can switch to the Private Key to get their E2E encryption. However, to do so, you must reset your account. This can result in IDrive deleting all your data from their servers.
IDrive Express is a service that can populate your online IDrive account with large amounts of data fast. It does so moving the data using a physical storage device. IDrive ships you a physical storage device. You connect it to your computer and use the IDrive Local Backup feature to quickly transfer the data you want to backup onto the physical storage device. Then you ship the device back to IDrive, where your data is downloaded, by the company, into your cloud account.
IDrive Photos is one of the newest features added to IDrive. It is a cloud storage app for photos from your iOS and Android devices. It offers unlimited storage space, and other capabilities such as a timeline view, auto uploads, and a favorites album.
Rather than backing up a select set of files, IDrive Mirror makes full image backups of Windows computers and servers. These backups can protect you against ransomware and other attacks. The increasing frequency and severity of such attacks is leading experts to call ransomware a national security risk.
3a8082e126