Extension: End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem

Record: kaal:position:2026-08-26-005 · 2026-08-26

Encryption at rest does not establish user-held state when the service provider controls the keys. Hofmann and Truong show why. In their analysis of end-to-end encrypted cloud storage, provider-held keys supply no protection once the provider is compromised. The relevant alternative encrypts files under keys managed by the user and evaluates confidentiality against a server with full access to its own infrastructure. This moves custody from a promise about data location to a test of decryption authority. The evidence is narrower than the general claim. The study concerns cloud storage, not agent working memory, and it documents flaws even in systems marketed as zero knowledge. User-managed keys can still fail through protocol defects, malicious client delivery, weak credentials, or metadata leakage. Those limits sharpen the classification. State is not user-held merely because ciphertext sits behind an ownership label. It is user-held only when the operator lacks the capability to recover the working contents without the user's participation. A credible system should test that condition against a compromised provider, not against its marketing description.

Affirmed commentary position. This record extends a source-bound scholarly claim but is not a verbatim paper claim.
Holds when
Current debate

End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem

Scholarly basis

kaal:claim:7314479-005
Wulf A. Kaal, Institutional Requirements for Sovereign Local Agent Runtimes (2026). SSRN: https://ssrn.com/abstract=7314479
Source PDF sha256: debace24a155ae924a155b1fafe98856d98cf83689feff2f87a32f1c06171ce6

Evidence and mapping

Evidence: peer-reviewed ACM CCS 2024 conference paper with complete public full text
Review tier: independent substantive scholarly-growth extension
Mapping confidence: 0.98
Mapping ambiguous: false

Topics

ai-and-agentsinstitutional-designdecentralizationend-to-end-encryptioncloud-storagekey-custodyevidence-provenance

Provenance

Affirmed in kaal-review:2026-08-26:scholarly-growth-7314479-005-reviewed-v1 on 2026-08-26. Review record.

Verify

Canonical markdown sha256: a9624f484e312d4c136fef8f1374c72614461f7ce811e840b40093b79bbbc992
curl -s https://wulfkaal.github.io/positions/2026-08-26-005.md | sha256sum