Password Protection of Dorico Files

Forgot to add, if a new format comes along for local storage I’ll move over to that if need be :slight_smile:

This thread was originally about data security, not backup. But when it comes to backup, a good recommendation is to have at least one on-site and one off-site backup (in case your house burns down). The off-site backup could be a cloud provider, or it could be local media that you store somewhere else; the advantage of a cloud backup is that it happens in near real time, and you don’t need to worry about transporting storage media somewhere else.

A lot of the choices here depend on your own personal feelings about risk, security, cost, and the value of what you’re backing up – so there’s no one-size-fits-all solution. I use Backblaze for online backup, and I do nightly backups to a local external hard drive which I replace every 5 years.

Excellent point about offsite backup!

I’ve seen too many problems with people trying to backup online while they are working in a project…if you want to use online do it when you’re not working :wink:

I think it depends how you’re doing the online backup. Backblaze and Carbonite and the like are always running in the background, but they are not aggressively backing up, usually delayed by a little bit, and they don’t place any file locks, so there are no problems with things I have open.

If you roll your own backup solution, you may run into issues.

Would you guys consider creating a feature to protect Dorico files with a password

Not a great idea if someone broke into your password protected Google Drive.

I keep my on-site backups in a small Phoenix media safe to protect them from fire and water damage:

Unfortunately, the price of this safe has increased significantly since I bought mine more than a decade ago.

I’ve got a fireproof safe for important stuff too :slight_smile:

Not all fireproof safes prevent melting, only paper from burning. Make sure you get the right kind of fireproof safe for the media you are saving.

Guitar Pro 8 has password protection for the files, so it would be possible for Dorico to develop this.

I’m sure it’s possible. The question is whether it’s something the Dorico Team have on their list of things to do. I may well have missed other requests for this here in the forum, but I’m not aware of a lot of people asking for it.

However, like all other requests this thread will have been read, and noted.

I for myself do not want password protection on my Dorico files. I don’t want to enter a password everytime I open a file, close it, work on another, reopen the previous file and need to type the password every time.

All my projects are stored locally and not on some external cloud and it is not problem at all, if I really move these projects to a cloud (which I do not do), to lock them via WinZip, WinRAR, 7Zip, or whatever utility is in use.

One way of making sure everything is safe, even in a cloud, is to use a tool like Cryptomator. This creates an encrypted container in the cloud that is mapped to a drive in Windows. I can install Cryptomator also on iOS and Android, so even there I can access the files, without the need to type the password every time. This is much safer than a simple password protection on Zip Files.

If it were implemented, I’m sure it would be optional; I don’t knew any program that requires you to put a password on each file.

Sure, but the OP was talking about Google Drive and there the problem starts. Never ever put things like your precious work on something from any cloud provider, unless there is a really strong level of encryption. None of the usual suspects is encrypting the data, just the transfer to the cloud and most of them, at least Google, Apple and Microsoft, are scanning your data.

So if you want to save a lot of files on Google drive you want all of them secure and that means a password on them. The next issue coming up here, do you use the same password for all of them… seriously? What happens if you have 20, 50 or more files in the cloud. How do you manage these passwords?

So my strong advice is, use some utility that encrypts everything on the cloud drive. No need for tons of passwords, but everything secured and untouchable for strangers.

If you don’t like Cryptomator, provider like pCloud or Proton have encryption available directly on their cloud systems.

“Citation required.”

Both Apple and Microsoft state that the data is encrypted, and their access is limited.

By default, iCloud Drive is encrypted; but Apple holds the keys for the purposes of recovery. There is an optional setting to allow end-to-end encryption, so that Apple doesn’t hold the keys.

If you could prove that Apple was actively scanning your data, then you’d have a major new story. This is the kind of stuff that professional security researchers constantly sink their teeth into.

MS does say that they scan for malware. Apple doesn’t make that claim.

Given that Google makes its money from selling data on users, one might have some grounds for caution there.

Well, that depends.

Apple has the key to your iCloud drive, so they can access your data (see the CSAM scanning discussion). You can of course enable ADP (Advanced Data Protection) which gives you end-to-end encryption.

However, even here some data are still excluded, like Mail, Contacts and Calendar.

There are known cases where Apple has given data from iCloud to government agencies, like this from 2016. They did it because of a court order, but they hand it over.

https://epic.org/documents/apple-v-fbi-2/

Regarding Microsoft, there are reports describing what happens if Microsoft believes you have bad content on OneDrive. What bad content is, only Microsoft knows. One example here.

Microsoft does not offer anything similar to ADP from Apple, so here you are on your own. Microsoft has the keys to your data.

The same is true for Google Drive, it is possible for Google to scan your data and take action, if they believe it is needed.

Ok, this discussion is now going into the wrong direction. All I wanted to explain is my opposition to passwords on Dorico files, but not discuss some political concerns about cloud providers, so I’m staying away here now.

In general though, I think it is still very valid to consider what entrusting your data to another entity means. Consider those companies that specialize in protecting and facilitating work on high value media assets. I’m thinking for example Avid NEXIS and their MediaCentral. I think there are cases where it would be silly to go that level, and cases where it would be negligent not to.

And cool if we talk about it? Avid seems to straddle the question themselves by offering cloud storage as an option (on Azure) local or hybrid. I think like Steinberg they can’t really afford to alienate any customer so they will facilitate what the customer requests.

I think those companies bring more than cloud storage and some encryption. I’m just saying that as a PSA; that we conversely shouldn’t expect more than is reasonable from just iCloud? Plus there the garden variety delete or overwrite or otherwise issues?

I think it’s worth at least looking at Hedge Mimiq ($300) or similar system. It does both cloud and local. Or others?

Thinking about this matter, and how people glibly say its easy to remove encryption from zip files (I disagree) the only proper solution to this that is completely secure is a hardware security key. Here’s a selection. Note that Google makes a good one.