<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://elvis.hcw.ac.at/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=VLaub</id>
	<title>Elvis Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://elvis.hcw.ac.at/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=VLaub"/>
	<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php/Special:Contributions/VLaub"/>
	<updated>2026-09-10T20:07:24Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.41.5</generator>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Cryptomator&amp;diff=14014</id>
		<title>Cryptomator</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Cryptomator&amp;diff=14014"/>
		<updated>2024-01-25T16:11:26Z</updated>

		<summary type="html">&lt;p&gt;VLaub: Created page with &amp;quot;== General ==  The open-source tool Cryptomator is an application for client-side encryption. This concept is applied when you want to upload your own data to a cloud service that needs to be protected, but you also want to ensure security. Client-side encryption refers to the concept of encrypting your own data on your own computer before uploading it to a cloud service.&amp;lt;ref&amp;gt;  https://support.google.com/a/answer/10741897?hl=de-de&amp;lt;/ref&amp;gt;  Cryptomator is a free tool due to...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== General == &lt;br /&gt;
The open-source tool Cryptomator is an application for client-side encryption. This concept is applied when you want to upload your own data to a cloud service that needs to be protected, but you also want to ensure security. Client-side encryption refers to the concept of encrypting your own data on your own computer before uploading it to a cloud service.&amp;lt;ref&amp;gt;  https://support.google.com/a/answer/10741897?hl=de-de&amp;lt;/ref&amp;gt;  Cryptomator is a free tool due to its open-source nature, which allows you to quickly and independently protect your own data and documents regardless of the price. &amp;lt;ref&amp;gt;  https://cryptomator.org/de/ &amp;lt;/ref&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Operation ==&lt;br /&gt;
The operation of the application is relatively simple. You can quickly download the .exe file from the Cryptomator website. A page on the website that opens automatically after downloading provides an introduction to using the tool.  &amp;lt;ref&amp;gt;  https://docs.cryptomator.org/en/latest/ &amp;lt;/ref&amp;gt; &amp;lt;br/&amp;gt;&lt;br /&gt;
If the application is opened, a window appears with the option to create a new folder, a so-called “vault,” with protected data. To do this, you must select a storage location, such as Google Docs, where the encrypted data should be stored. Then a password must be set for it. After successfully creating the folder and unlocking it by entering the password, a virtual drive is created in the file manager for each unlocked vault. The decrypted documents stored there are located in this virtual drive. In the meantime, only encrypted data can be found in the cloud service folder. Any number of vaults can be created. &lt;br /&gt;
 &lt;br /&gt;
[[File:Cryptomator.png|caption]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
At no time are decrypted data stored on the hard drive of your own computer. These are decrypted on-the-fly when accessed. &amp;lt;ref&amp;gt;  https://docs.cryptomator.org/en/latest/security/security-target/ &amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Security ==&lt;br /&gt;
Without the use of client-side encryption, data in cloud services would only be encoded during transmission and otherwise potentially stored in plaintext. This would allow attackers to read, steal, or manipulate personal data stored in the cloud in the event of a successful cloud hack. Cloud service providers also have the ability to read the data they are given if it is not passed on in an encrypted form. Cryptomator is a tool for greater security, both against hackers and cloud service providers themselves. The encryption is performed using the AES method and a key length of 256 bits.  &amp;lt;ref&amp;gt;  https://cryptomator.org/de/&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Encryption  ==&lt;br /&gt;
The documentation of the tool provides a comprehensive description of how file encryption works. Cryptomator is not a complete replacement for other encryption measures. To ensure functional synchronization with the cloud, some metadata is not encrypted. These include access, modification, and creation timestamps of files and folders, the number of files and folders in a vault and in the folders, as well as the size of the stored files.  &amp;lt;ref&amp;gt;  https://docs.cryptomator.org/en/latest/security/architecture/ &amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Other == &lt;br /&gt;
The preferred frontends for accessing files in cloud storage are WinFsp for Windows, macFUSE for macOS, and FUSE for Linux. If not available, Cryptomator will use WebDAV (an HTTP-based protocol) because it is mainly supported on every operating system.  &amp;lt;ref&amp;gt;  https://docs.cryptomator.org/en/latest/security/architecture/ &amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;/div&gt;</summary>
		<author><name>VLaub</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Cryptomator.png&amp;diff=14013</id>
		<title>File:Cryptomator.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Cryptomator.png&amp;diff=14013"/>
		<updated>2024-01-25T16:09:45Z</updated>

		<summary type="html">&lt;p&gt;VLaub: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>VLaub</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Sans_Cloud_ACE&amp;diff=14012</id>
		<title>Sans Cloud ACE</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Sans_Cloud_ACE&amp;diff=14012"/>
		<updated>2024-01-25T16:01:57Z</updated>

		<summary type="html">&lt;p&gt;VLaub: Created page with &amp;quot;== Summary ==  SANS Cloud ACE is an initiative that offers a variety of training and courses to educate and further train cloud security experts. According to the SANS Institute, the ongoing transition and increased use of cloud services by companies is leading to a significant increase in the need for cloud security specific professionals, for whose training the institute’s initiative should help. &amp;lt;ref&amp;gt; https://www.sans.org/cloud-security/ace/ &amp;lt;/ref&amp;gt;  == SANS Institut...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary ==&lt;br /&gt;
&lt;br /&gt;
SANS Cloud ACE is an initiative that offers a variety of training and courses to educate and further train cloud security experts. According to the SANS Institute, the ongoing transition and increased use of cloud services by companies is leading to a significant increase in the need for cloud security specific professionals, for whose training the institute’s initiative should help. &amp;lt;ref&amp;gt; https://www.sans.org/cloud-security/ace/ &amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== SANS Institute ==&lt;br /&gt;
&lt;br /&gt;
SANS is a leading institution for education and training in the field of IT security. The acronym SANS stands for SysAdmin, Audit, Network and Security.&amp;lt;ref&amp;gt;  https://www.wikiwand.com/en/The_Escal_Institute_of_Advanced_Technologies&amp;lt;/ref&amp;gt;  The organization was founded in 1989 and is the world’s largest source of IT security training and certification according to its own claims. &amp;lt;ref&amp;gt;https://sans.org&amp;lt;/ref&amp;gt; &amp;lt;br /&amp;gt; &lt;br /&gt;
SANS offers various methods to deliver the course content for every required level, including degree programs, certificates, and training. Some of the subfields include “Digital Forensics and Incident Response”, “Cyber Defense and Blue Team Operations”, and “Cloud Security”. These courses are led by experienced industry experts. Training events in various cities are also part of the SANS offerings. A dedicated blog, newsletter, and podcasts provide the opportunity to stay up-to-date on the latest security topics. &amp;lt;ref&amp;gt;https://sans.org&amp;lt;/ref&amp;gt; &amp;lt;br /&amp;gt; &lt;br /&gt;
Depending on the specific subfield of IT security, SANS offers various programs in the form of a series of online courses for in-depth knowledge. One of these programs is SANS Cloud ACE. &amp;lt;ref&amp;gt;https://sans.org&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Topics and Contents ==&lt;br /&gt;
&lt;br /&gt;
Participation in the SANS Cloud ACE Program is chargeable, and therefore not all learning content is freely accessible. However, there is a variety of videos of recorded workshops available on YouTube. These workshops usually last between 20 minutes and an hour and cover various topics related to cloud security. The workshops are designed in a practical way. They do not focus on a specific security risk in the field of cloud computing, but rather on the handling of one of the three cloud security providers, Amazon Web Services, Google Cloud, and Microsoft Azure. In general, the content focuses more on general precautions and misconfigurations of the three most famous cloud service providers. &amp;lt;ref&amp;gt; https://www.youtube.com/@SANSCloudSecurity &amp;lt;/ref&amp;gt; &amp;lt;br /&amp;gt; &lt;br /&gt;
The speakers are security specialists who are supposed to pass on the knowledge they have acquired through their previous professional experience to the participants. Their workshops are often held online so that people from all over the world can participate regardless of their location. Generally, the presentation always consists of a series of slides summarizing the core elements of the course content. Another characteristic is that many workshops not only convey theory but also practical exercises for the participants so that they can apply what they have learned and consolidate their knowledge. Slack is often used as a messenger service for asking questions during the workshop. The speakers are cooperative and apparently motivated to answer participants’ questions. &amp;lt;ref&amp;gt;  https://www.youtube.com/@SANSCloudSecurity &amp;lt;/ref&amp;gt; &amp;lt;br /&amp;gt; &lt;br /&gt;
Outside of the workshops, SANS also offers podcasts and blogs on cloud security for interested parties, where you can follow regular updates on the latest developments in cloud security. &amp;lt;ref&amp;gt;  https://www.sans.org/cloud-security/ace/ &amp;lt;/ref&amp;gt; &amp;lt;br /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Concepts ==&lt;br /&gt;
&lt;br /&gt;
Currently, there are ten courses available for SANS Cloud ACE that are specifically designed for cloud security. These courses are listed in orange on the Flight Plan image below and are organized from basic knowledge (top) to more specific and in-depth topics (bottom). The courses are classified from basic knowledge to management on the left side of the names, and icons of different types of aircraft underline the top-to-bottom classification. This metaphorically represents that as a SANS Cloud ACE, you start as a pilot with a small plane and switch to larger planes, symbolizing an expanded knowledge of cloud security by completing more courses. The five columns to the right of the courses in the graph represent the five career orientations covered by the program. The gray circles at the intersections between the work areas and the courses indicate whether the course in the corresponding row is suitable for people in this field or individuals who wish to further their education in this area.  &lt;br /&gt;
&lt;br /&gt;
[[File:Cloud-Flight-Plan.jpg|500px]]&lt;br /&gt;
&lt;br /&gt;
Some courses include a signature in the graph, each of which refers to a specific GIAC certification. GIAC stands for ‘Global Information Assurance Certification’&amp;lt;ref&amp;gt;  https://www.giac.org/about/company-info/?msc=main-nav &amp;lt;/ref&amp;gt; and offers the opportunity to obtain certification after completing the corresponding training. This allows course participants to demonstrate their knowledge and acquire a document with which they can prove their newly acquired knowledge to themselves and their employer.  &amp;lt;ref&amp;gt;  https://www.giac.org/about/company-info/?msc=main-nav &amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Gaining an ACE status ==&lt;br /&gt;
&lt;br /&gt;
As the name implies, participants in the SANS Cloud ACE program have the opportunity to become a ‘Cloud ACE’. As shown in the Flight Plan, the program is divided into five more specific job categories:&lt;br /&gt;
* Cloud Security Analyst: Use of cloud security solutions for defense and attack detection&lt;br /&gt;
* Cloud Security Architect: Designing cloud security solutions&lt;br /&gt;
* Cloud Security Engineer: Developing solutions for cloud security&lt;br /&gt;
* Dev Sec Ops: Developing, implementing, and managing secure systems&lt;br /&gt;
* Cloud Detection and Response: Detecting threats by monitoring and testing cloud environments&lt;br /&gt;
Participants in the program choose one of the five specializations according to their own job or interests. For each category, there is a journey that must be completed to obtain the title of that journey. Each journey includes three courses, selected according to the topic of the field of work. However, to be designated as a SANS Cloud ACE, one can also take only one course and obtain the corresponding GIAC certification. The target groups are people with previous knowledge in the field of IT and cloud security, but also career changers with the desire to further their education, as the program offers introductory courses on the topic.  &amp;lt;ref&amp;gt;  https://www.sans.org/cloud-security/ace/ &amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==References==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &lt;/div&gt;</summary>
		<author><name>VLaub</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Cloud-Flight-Plan.jpg&amp;diff=14009</id>
		<title>File:Cloud-Flight-Plan.jpg</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Cloud-Flight-Plan.jpg&amp;diff=14009"/>
		<updated>2024-01-25T15:41:59Z</updated>

		<summary type="html">&lt;p&gt;VLaub: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>VLaub</name></author>
	</entry>
</feed>