• wampus@lemmy.ca
    link
    fedilink
    English
    arrow-up
    3
    ·
    edit-2
    20 days ago

    Sure - here you go.

    I find the appendix the easiest part to parse. It basically lists their responses/mitigation attempts, and notes that they all basically fail to protect data sovereignty when stuff is foreign-centric. The encryption note doesn’t generally apply to live-service programs (eg. you “can” store fully encrypted cloud backups, so long as you control the keys – but not something like a portal for users to login/access regularly). They list masking, but also basically show it’s not realistic/practical, nor has it been attempted/tested in real world deployments. The rest are all “this mitigation doesn’t actually do anything for this issue”.