{
 "@context": "https://schema.org",
 "@type": "Claim",
 "@id": "https://wulfkaal.github.io/positions/2026-08-26-005",
 "identifier": "kaal:position:2026-08-26-005",
 "additionalType": "https://wulfkaal.github.io/positions/schema.json#AffirmedPositionClaim",
 "name": "User Controlled Decryption Custody Test",
 "text": "Encryption at rest does not establish user-held state when the service provider controls the keys. Hofmann and Truong show why. In their analysis of end-to-end encrypted cloud storage, provider-held keys supply no protection once the provider is compromised. The relevant alternative encrypts files under keys managed by the user and evaluates confidentiality against a server with full access to its own infrastructure. This moves custody from a promise about data location to a test of decryption authority.\n\nThe evidence is narrower than the general claim. The study concerns cloud storage, not agent working memory, and it documents flaws even in systems marketed as zero knowledge. User-managed keys can still fail through protocol defects, malicious client delivery, weak credentials, or metadata leakage. Those limits sharpen the classification. State is not user-held merely because ciphertext sits behind an ownership label. It is user-held only when the operator lacks the capability to recover the working contents without the user's participation. A credible system should test that condition against a compromised provider, not against its marketing description.",
 "author": {
  "@type": "Person",
  "name": "Wulf A. Kaal",
  "identifier": "https://orcid.org/0009-0008-7840-1847"
 },
 "datePublished": "2026-08-26",
 "dateModified": "2026-08-26",
 "creativeWorkStatus": "Affirmed",
 "responseType": "extension",
 "keywords": [
  "ai-and-agents",
  "institutional-design",
  "decentralization",
  "end-to-end-encryption",
  "cloud-storage",
  "key-custody",
  "evidence-provenance"
 ],
 "scope_conditions": [
  "The response is limited to the exact full-text propositions and the one mapped Kaal claim.",
  "External evidence level: peer-reviewed ACM CCS 2024 conference paper with complete public full text.",
  "Mapping review tier: independent substantive scholarly-growth extension.",
  "The paper studies cloud-storage confidentiality and integrity, not AI agent runtimes or volatile working memory.",
  "User-managed keys do not by themselves establish a secure design because protocol defects, malicious client delivery, and weak credentials can expose plaintext.",
  "The provider may still learn metadata even when file contents remain confidential.",
  "The study evaluates five named providers and does not prove security or insecurity for every end-to-end encrypted service."
 ],
 "currentDebate": {
  "name": "End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem",
  "url": "https://doi.org/10.1145/3658644.3690309"
 },
 "extends": {
  "identifier": "kaal:claim:7314479-005",
  "url": "https://wulfkaal.github.io/claims/7314479-005",
  "citation": "Wulf A. Kaal, Institutional Requirements for Sovereign Local Agent Runtimes (2026). SSRN: https://ssrn.com/abstract=7314479",
  "paper": "Wulf A. Kaal, Institutional Requirements for Sovereign Local Agent Runtimes",
  "authors": [
   "Wulf A. Kaal"
  ],
  "year": "2026",
  "ssrn": "https://ssrn.com/abstract=7314479",
  "source_pdf_sha256": "debace24a155ae924a155b1fafe98856d98cf83689feff2f87a32f1c06171ce6"
 },
 "isBasedOn": [
  {
   "@id": "https://wulfkaal.github.io/claims/7314479-005"
  },
  {
   "@type": "CreativeWork",
   "name": "End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem",
   "url": "https://doi.org/10.1145/3658644.3690309"
  }
 ],
 "batch_id": "kaal-review:2026-08-26:scholarly-growth-7314479-005-reviewed-v1",
 "review_provenance": "https://wulfkaal.github.io/positions/by-claim/7314479-005.html",
 "publicationStatus": "public",
 "recordTypeNote": "Dated commentary position extending a scholarly corpus claim. Not a verbatim claim extracted from the paper.",
 "isPartOf": {
  "@id": "https://wulfkaal.github.io/positions/index.json"
 },
 "version": "1.0",
 "canonical_url": "https://wulfkaal.github.io/positions/2026-08-26-005",
 "canonicalForm": "https://wulfkaal.github.io/positions/2026-08-26-005.md",
 "candidateId": "kaal:response-candidate:2026-08-26:scholarly-growth-7314479-005-user-controlled-decryption-01",
 "evidenceLevel": "peer-reviewed ACM CCS 2024 conference paper with complete public full text",
 "reviewTier": "independent substantive scholarly-growth extension",
 "mappingConfidence": 0.98,
 "mappingAmbiguous": false,
 "mappingMethod": "independent substantive scholarly-growth one-to-one review",
 "mappingWhyRelevant": "The paper independently separates provider-held from user-managed decryption authority and evaluates claimed provider incapacity under full server compromise. That mechanism directly extends Kaal's user-held-state test while remaining limited to cloud-storage confidentiality and integrity.",
 "sourceProvenance": {
  "source": "peer-reviewed ACM CCS 2024 conference paper with complete public full text",
  "sourceRecordId": "doi:10.1145/3658644.3690309",
  "doi": "10.1145/3658644.3690309",
  "canonicalUrl": "https://doi.org/10.1145/3658644.3690309",
  "publicFullTextUrl": "https://brokencloudstorage.info/paper.pdf",
  "retrievedAt": "2026-08-27T03:44:08.017Z",
  "fullTextPdfSha256": "667da3599b74f8396d68d31f741cafd89f395c87a2238125c095937eabea5b28",
  "extractedTextSha256": "9c2a41c35149961f8db9f219e42f15bacb4f51e76513ebde6beded061941d508",
  "openAlexRecordSha256": "d58dcf6ae4ce6a7b10c4d79c07179102bd8839573aecc8d79978eb42551d7a5e",
  "primaryEvidenceReceiptSha256": "f7678d7507fc8a550b588c6ad1bcea83c94c5fd0da34640c55f5fb7176da9e59",
  "sourceProposition": "Hofmann and Truong show that provider-controlled encryption keys do not protect user data after provider compromise, while end-to-end encryption instead uses keys managed by the user and evaluates security against a malicious server.",
  "sourcePropositionSha256": "94c6ee12cb0873cb1de25a4541f89c32b095ee30eb80dc2dd4840f29ee9c06b1",
  "sourceEvidenceSetSha256": "6d1c4e9946f1814d0eeb7c4308a4f28a92fc6f56685c54eb1d0cc07199c214a5",
  "sourceEvidencePassages": [
   {
    "text": "Almost all of these providers use encryption-at-rest to protect the user data from external attackers. If we, however, consider the case in which the provider itself is compromised, encryption-at-rest does not provide any protection since the provider controls the encryption keys.",
    "locator": {
     "publication": "ACM CCS 2024",
     "pdfPage": 1,
     "section": "1. Introduction"
    },
    "sha256": "1dd505837bd85bfa9a99a2d7704fee1ca872f45e50fd6bddbeac38784cc249a9"
   },
   {
    "text": "To secure user data in this setting, which we call the compromised, or malicious, server setting, providers have started deploying end-to-end encryption (E2EE), where user files are encrypted with keys managed by the user, rather than the server.",
    "locator": {
     "publication": "ACM CCS 2024",
     "pdfPage": 1,
     "section": "1. Introduction"
    },
    "sha256": "abd46a9b9ea8dd08e305b5b966e65d6a7f233fe28fbb4fac2990ba543ac07305"
   },
   {
    "text": "We analyse the end-to-end encryption of these providers in the natural setting of a compromised server. This is a fair expectation for E2EE cloud storage: security should be preserved even if the attacker has full access to the server and can directly interact with the user.",
    "locator": {
     "publication": "ACM CCS 2024",
     "pdfPage": 1,
     "section": "1.1. Our Contributions"
    },
    "sha256": "5c436b4e974a52ef4578e8038de3f02bd4bbded9db53a02de104707a15a5dce5"
   },
   {
    "text": "This threat model also aligns with the advertisement of various cloud providers, as many of them claim to be unable to access user data thanks to what they dub “zero-knowledge encryption”.",
    "locator": {
     "publication": "ACM CCS 2024",
     "pdfPage": 1,
     "section": "1.1. Our Contributions"
    },
    "sha256": "c2deb1650772cb05ca4ffce145dce196f5d3a6e8ea5bdf29555eaa9942d6735e"
   },
   {
    "text": "Our attacks invalidate the marketing claims made by the providers of these systems, showing that a malicious server can, in some cases, inject files in the encrypted storage of users, tamper with file data, and even gain direct access to the content of the files.",
    "locator": {
     "publication": "ACM CCS 2024",
     "pdfPage": 1,
     "section": "Abstract"
    },
    "sha256": "f4c28484f9ad11b62cd05e59493547c739f23b14635fb077e06ed413b7abc529"
   }
  ],
  "workId": "work:doi:10.1145/3658644.3690309",
  "workAuthors": [
   "Jonas Hofmann",
   "Kien Tuong Truong"
  ],
  "workPublishedAt": "2024-10",
  "identityKeys": [
   "doi:10.1145/3658644.3690309",
   "pdf:667da3599b74f8396d68d31f741cafd89f395c87a2238125c095937eabea5b28",
   "proposition:94c6ee12cb0873cb1de25a4541f89c32b095ee30eb80dc2dd4840f29ee9c06b1"
  ],
  "claimMappings": [
   {
    "claimId": "kaal:claim:7314479-005",
    "claimUrl": "https://wulfkaal.github.io/claims/7314479-005",
    "rank": 1,
    "confidence": 0.98,
    "method": "independent substantive scholarly-growth one-to-one review",
    "whyRelevant": "The paper independently separates provider-held from user-managed decryption authority and evaluates claimed provider incapacity under full server compromise. That mechanism directly extends Kaal's user-held-state test while remaining limited to cloud-storage confidentiality and integrity.",
    "ambiguous": false
   }
  ],
  "substantiveReview": {
   "reviewedAt": "2026-08-27T03:44:08.017Z",
   "sourceIdentityVerified": true,
   "authorIndependenceVerified": true,
   "kaalReferenceFoundInSource": false,
   "temporalIndependence": "The conference paper was published in 2024, before Kaal's 2026 paper.",
   "canonicalPublicStatusVerified": true,
   "peerReviewedStatusVerified": true,
   "retractionOrSupersessionFound": false,
   "propositionFidelityVerified": true,
   "mechanismCorrespondence": "provider-controlled keys fail under provider compromise, while user-managed keys define the end-to-end alternative",
   "compatibleScope": "cloud-storage confidentiality and integrity, limited because the source does not study AI agent working memory",
   "responseWordingDefensible": true,
   "oneToOneExtendsMapping": true,
   "exactSupportingQuotesVerified": true,
   "nonOverlap": {
    "candidateIdMatches": false,
    "canonicalUrlMatches": false,
    "propositionHashMatches": false,
    "priorPositionForClaim": false
   },
   "limitations": [
    "The paper studies cloud-storage confidentiality and integrity, not AI agent runtimes or volatile working memory.",
    "User-managed keys do not by themselves establish a secure design because protocol defects, malicious client delivery, and weak credentials can expose plaintext.",
    "The provider may still learn metadata even when file contents remain confidential.",
    "The study evaluates five named providers and does not prove security or insecurity for every end-to-end encrypted service."
   ],
   "rejectionReasonsRecorded": true
  },
  "contentMap": {
   "proposition": "User-held state requires decryption authority that the provider does not possess.",
   "evidenceLayer": "peer-reviewed ACM CCS 2024 conference paper with complete public full text",
   "strongestLimitation": "The source concerns cloud storage rather than agent working memory.",
   "consequence": "Encryption labels do not establish custody when the operator controls recovery keys.",
   "requestedAction": "Test confidentiality against a compromised provider and verify user-controlled decryption."
  },
  "stylePack": {
   "profile": "M1 early sole-author baseline v1.2.0",
   "verifiedProfileWorks": [
    "1428387",
    "2150377",
    "2267560"
   ],
   "sameRegisterPassagePackAvailable": true,
   "limitation": "The short public position permits only bounded stylometric comparison."
  },
  "m1Validation": {
   "status": "M1-PASS-WITH-LIMITS",
   "deterministicGate": "pass",
   "hardFailures": 0,
   "warnings": 0,
   "words": 173,
   "reason": "The publication-bound position passed strict and public deterministic controls against a five-passage, three-work style pack. Its short length limits stylometric comparison."
  }
 },
 "userAffirmation": "Authorized under public authority SHA-256 87aad20196a753015a36d970f742c885eb763efdbada4869949bfffe3298130c and event supersession SHA-256 7d47ef36085c4dce590f287c986e4106f3bf35a7da5a25322d6fc3d4abf456d4. Publication remains receipt-bound to successful workflows and exact live-byte verification.",
 "sha256": "a9624f484e312d4c136fef8f1374c72614461f7ce811e840b40093b79bbbc992"
}
