Matomo

End-to-end encryption and multi-device synchronisation for 6M users | Cossack Labs
Case studies
End-to-end encryption and multi-device synchronisation for 6M users

End-to-end encryption and multi-device synchronisation for 6M users

SUMMER 2019 Mobile application Cloud data security
End-to-end encryption and multi-device synchronisation for 6M users

Overview

Industry

  • productivity apps
  • note-taking apps

Technology stack

  • iOS
  • macOS
  • Apple cloud backend

Regulations

  • GDPR
  • Encryption Export Regulations

Challenges

[01]

Transparency for users

Bear app doesn't have externally enforced strict security requirements (unlike, for instance, fintech/banking-related apps) so cannot force users to create strong and unique passwords.

[02]

Losing data is out of question

Losing or not being able to decrypt user notes is a significant threat and reputational risk. The Bear team can't access iCloud database of their users, meaning there's no “admin way” to help users if they forget or lose their passwords.

[03]

Security that doesn't ruin UI/UX

Smooth user experience is a part of UVP, so the encryption scheme should not complicate the UX, but rather overcome the limitations.

[04]

Mobile platform specifics

Mobile users have multiple devices, some of them online and some of them offline, which requires careful synchronisation of encrypted data and keys.

Technology requirements

Technology requirements

End-to-end encryption

End-to-end encryption of user notes should be based on solutions compatible with Apple platform, but at the same time, it should be easy to migrate to Web/Electron platform that Bear team has in the roadmap.

Multi-device synchronisation

Support of multi-device synchronisation for encrypted notes and notes' passwords since a typical Bear user uses the app on several Apple devices (iPhone, iPad, MacBook).

Easy to maintain cryptography

Encryption engine should be easy to maintain, support, and update by non-cryptographers, giving the Bear dev team the necessary flexibility for introducing changes.

Solution

We designed end-to-end encryption engine with the following properties:

Besides the cryptographic core, we've also provided a number of security recommendations for development aligned with “defense in depth” approach:

Results and outcomes

Our solution provides strong security guarantees, uses platform-specific security controls, and is fully integrated into the Bear application flow without ruining the user experience.

The new secured Bear app had a very successful release after a short beta-testing phase. End-to-end encryption was one of the release's main highlights. Our engineers worked closely with Bear app's team, designing cryptographic protocol, helping with implementation, suggesting security improvements, and verifying the results.

The resulting solution attracted security-aware users, potentially allowing Bear app to increase and consolidate their user base and provided a clear competitive advantage over their competitors.


Up next

Got a challenge that's still standing?

Let’s start a conversation.

Start a conversation

Get whitepaper

Application form

Our team will review your resume and provide feedback
within 5 business days

Thank you!

We’ve received your request and will respond soon.

Your resume has been sent!

Our team will review your resume and provide feedback
within 5 business days