Passwords and Backup Security
by Steve Eschweiler
Secure Online Backup
In the “What Makes an Online Backup Solution, Secure?” post, I wanted to address server-side eavesdropping so I’ll do my best to describe it in “English”.
Your online backups are only as secure as your password. What a lot of folks don’t realize is that entering a password online, even with SSL encryption and an HTTPS connection, is not 100% secure. You may wonder why this is so. Afterall, online banking uses SSL encryption when you access your bank account online. Well, the reason why it’s not 100% secure is due to the fact that SSL only encrypts the communication between your computer and the server. Once data enters the server, it is no longer secured by SSL. This is because the server needs to interpret whatever data you sent from your browser to the server. So the data on the server is open to eavesdropping. I’ll be honest and say that eavesdropping is not an easy thing to do. In theory, you first need to gain access to the server. Secondly, you need to install a program on the server that “listens” or “scans” for this type of information. Both of these are hard to do and there measures that a Server Administrator can put in place to help prevent this but it’s still not 100% secure.
SecureBackup avoids the problem altogether by the way in which it was designed. We don’t have a copy of your password so you don’t need to enter it online. Your password is created on your computer and is never transmitted across the Internet. This provides for a level of protection above and beyond what SSL alone can provide. If no password is ever transmitted, no password can ever be intercepted.
This is why SecureBackup requires you to sign up for service within the software rather than online. The main idea here is that everything is created and encrypted right on your computer.
Your Password is Your Security
As mentioned in some of my other posts, your online backups are only as secure as your password. If you want to keep them from prying eyes, you need to safeguard your password. With SecureBackup, we have done what we can on our end to protect it. Secure password protection is the key to having a secure, online backup service.



