Decentralized Storage: The Path to Ultimate Data Privacy and Ownership
By FF Newsroom · 9 May 2023

Data ownership and privacy has become increasingly relevant as we navigate the digital age. The convenience and ubiquity of centralized storage providers like OneDrive, GDrive, and Dropbox have made them the default choice for many users. However, these centralized services come with inherent risks and compromises that the development of blockchain technology could help overcome.
Centralized storage providers have simplified the user experience by offering easy-to-use applications and APIs. But this convenience comes at the cost of relinquishing control over our data. As users sign up for these services, a closer look at the terms and conditions shows that they often include data access and usage restrictions. Moreover, it's different from the total privacy that users believe it is, with the storage provider often having the rights to specific data for marketing and advertising purposes.
The downfalls of centralized storage have been felt across recent years with cases such as the 2018 Google+ bug. In October 2018, Google showed that a bug within the system had exposed the private information of over 500,000 accounts for over three years. In the process of shutting down servers, an update in November caused another 52.5 million users to be impacted, with non-public profile data being exposed to malicious actors. December 2020 saw another breach of the Google Cloud Service, causing sensitive information from vaccine producer Pfizer to be stolen.
Not Your Keys, Not Your Data
Centralized storage providers often market themselves as highly secure and private. They do this by using what is known as at-rest encryption, meaning that the data is fully encrypted when on the provider's disk. If an external party were to get access to the disk, the data would be fully encrypted, useless to them without the encryption keys.
But what most users need to realize is that the storage provider is the one that has access to the encryption keys for our data, allowing them to access the data on the drives freely. This reality raises concerns about the actual ownership of our data and the potential for misuse by the very companies that promise to protect it. It also raises the question, if you do not hold the keys to your data, do you truly own it any longer?
You can visualize the flow of data in a centralized scenario like this:
- You log into the storage provider's service.
- The storage provider accesses the encryption key to your data.
- Your data is decrypted using the storage provider's key.
- The data is sent to you.
- You log into the storage provider's sealed storage space using your unique crypto wallet.
- The encryption key held within the wallet is used to decrypt the data.
- The data is sent back to you.