I made Google Drive personal with out giving up Google Drive

I have never put anything I classify as very confidential on Google Drive. It’s not as a result of I imagine Google will in the future blackmail me, but when it isn’t my server, I should not act like I fully belief it. So I saved my children’ images and confidential spreadsheets away from it.
But I examined Cryptomator, and as soon as I noticed what Google Drive was really getting, I noticed I did not have to maintain my most delicate recordsdata away from it.
I put my actual recordsdata behind a vault Google Drive was already syncing
Then I went searching for what really left my laptop
I had heard about Cryptomator, and it sounded fascinating, however I wanted to check it firsthand. So, I constructed a Cryptomator vault known as “Vault for MUO”, and dropped in some recordsdata; a mixture of CSV exports, some photos, and spreadsheets. The objective was to present it the sort of folders I sometimes like to maintain secure.
This folder sat inside my Cryptomator folder, which sat inside my Google Drive sync folder on my laptop. When you launch Cryptomator and unlock the vault, it mounts the vault as a digital drive in your laptop. I opened this mounted vault and will see all of the recordsdata I had dropped into that folder. They opened as anticipated and retained the unique filenames. Nothing appeared totally different or misplaced.
This felt odd at first, nevertheless it’s your entire level of this service. It’s not asking you to vary the way you usually use recordsdata and folders. It requires you to belief that recordsdata leaving your laptop will not be recognizable. However, this requirement was the half I did not need to tackle religion. So I went searching for what Google Drive was really holding.
I opened Google Drive and did not acknowledge my very own folder
Here’s what the cloud-side view confirmed me, merchandise by merchandise
The copy Google Drive held did not appear to be what I had saved. I did not see my images or spreadsheet, reasonably it confirmed folders named “c” and “d”, a file known as vault.cryptomator (with a backup), a masterkey.cryptomator (with its personal backup), and a plain-text file Cryptomator drops into each vault. Those recognizable Cryptomator recordsdata additionally made one factor apparent: Google Drive might inform that this was an encrypted vault, regardless that it could not see the recordsdata inside it.
It will get stranger once you open “c” or “d”. All you get are scrambled strings combining letters and numbers that basically don’t map to something you’ve gotten. Encrypted identifiers changed my daughter’s folder names, the camera-generated picture filenames, and the CSV titles. This was far totally different from Google Drive hiding my recordsdata behind a password. It merely by no means acquired a readable model to begin with.
|
What Google Drive sees |
Normal add |
Inside the Cryptomator vault |
|---|---|---|
|
Filenames |
Readable |
Encrypted |
|
Folder names |
Readable |
Obfuscated/encrypted |
|
File contents |
Readable |
Encrypted |
|
Recognizable content material |
Yes |
No |
|
File measurement |
Visible |
Visible |
The final row was essentially the most stunning for me. I used to be pondering an encrypted file blurs the precise file measurement. Apparently, Cryptomator dropped file-size obfuscation in model 1.2.0. Hiding file measurement is a unique drawback, and it is not one thing the present vault format tries to unravel.
The fundamental sync workflow does not change. Google Drive nonetheless syncs the encrypted vault throughout my gadgets, whereas its versioning and restoration options function on the encrypted recordsdata reasonably than my authentic recordsdata. The solely place the place the folder seems regular is on my machine after I unlock the vault.
The recordsdata vanished—however the proof that I had recordsdata remained
Where the privateness declare really stops
It was tempting to say Google Drive sees nothing after seeing the model that Google Drive holds. But that will not be precisely true.
Google Drive nonetheless sees {that a} vault exists, how a lot knowledge the saved recordsdata occupy, and metadata equivalent to file and folder timestamps and counts. Cryptomator does not conceal all metadata as a result of the cloud service nonetheless wants sufficient data to synchronize the vault. What it does not get is the readable content material, authentic filenames, or authentic listing construction.
In different phrases, Cryptomator takes away the readable names and contents with out hiding each piece of metadata concerning the vault.
Cryptomator encrypts file contents however does not have an effect on Google account logs equivalent to login historical past or machine knowledge.
I modified what I let Google Drive see
Opening this vault as soon as was fascinating, however the true check was dwelling with it. I made sure modifications: added a number of new images, renamed a CSV file, and deleted a folder. After letting Google Drive sync, I locked my vault. Google Drive had no concept what the recordsdata had been, however that folder nonetheless synced completely as a result of it observed one thing had modified.
UtilizingCryptomator provides an additional step—locking and unlocking the vault—which is a few type of friction. You additionally do not get previews of the vault content material, and search stops working inside it; it is simply not potential for Google Drive to parse what’s hidden.
These are sensible prices of utilizing this instrument, however they’re a good value to pay for protecting my recordsdata encrypted with out giving up Google Drive. Cryptomator tops my listing of useful tools that improve Google Drive security.
- OS
-
Windows, macOS, Linux
- Developer
-
Sebastian Stenzel
- Price mannequin
-
Free, Open-source
Cryptomator is an open-source utility for encrypting recordsdata. It lets you retailer recordsdata securely in a cloud service or community drive.
