Extension: End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem
Encryption at rest does not establish user-held state when the service provider controls the keys. Hofmann and Truong show why. In their analysis of end-to-end encrypted cloud storage, provider-held keys supply no protection once the provider is compromised. The relevant alternative encrypts files under keys managed by the user and evaluates confidentiality against a server with full access to its own infrastructure. This moves custody from a promise about data location to a test of decryption authority. The evidence is narrower than the general claim. The study concerns cloud storage, not agent working memory, and it documents flaws even in systems marketed as zero knowledge. User-managed keys can still fail through protocol defects, malicious client delivery, weak credentials, or metadata leakage. Those limits sharpen the classification. State is not user-held merely because ciphertext sits behind an ownership label. It is user-held only when the operator lacks the capability to recover the working contents without the user's participation. A credible system should test that condition against a compromised provider, not against its marketing description.
ai-and-agentsinstitutional-designdecentralizationend-to-end-encryptioncloud-storagekey-custodyevidence-provenance