Tide uses “cyber herd immunity” to describe a security design that spreads cryptographic authority across servers operated by different organizations, rather than keeping a complete key under one organization’s control. The phrase is an analogy, not a promise that breaches become impossible: Tide’s proposal depends on distributed participation, node independence and assumptions in its own threat model.
What Tide means by “cyber herd immunity”
The phrase comes from a Tide Foundation announcement published on October 20, 2021. Tide described its approach as “blind secret processing”: access-key fragments are distributed among servers managed by multiple organizations, so no single organization holds the complete key. Tide co-founder Michael Loewy said, “To really solve the problem, we need an entirely new way of thinking.” That is the company’s framing of its proposal, not an independent assessment of its security. Tide’s 2021 announcement
The underlying idea is distributed authority. If one server or administrator is compromised, an attacker may not obtain enough information or cooperation to carry out a protected cryptographic operation. The system’s design aims to make compromise of one participant insufficient, rather than relying on a single central key holder. Tide’s SDK documentation expresses the premise this way: “Tide is an approach to security architecture based on a simple premise: if a secret exists in one place, it can be stolen from that place.” TideCloak SDK documentation
How the threshold design is supposed to work
Tide’s current architecture documentation describes a design with 20 nodes and a threshold of 14. In practical terms, the system is configured so that a qualifying operation requires participation from the threshold specified by Tide; the complete authority is not meant to reside with one node. The “14 out of 20” figure is a vendor-stated architecture parameter, not a measured result or universal cryptography standard. Tide’s architecture documentation
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problems#1 Best Overall
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
This model changes the security question from “Can one key store be stolen?” to “Who controls the nodes, how many can be compromised or collude, and can enough nodes remain available to authorize an operation?” Distributing nodes across genuinely independent organizations may reduce dependence on any one administrator. If multiple nodes are controlled by the same party, share infrastructure, or are compromised together, the intended separation can be weakened.
What the system protects against—and what it does not establish
Tide’s threat model describes protection against coalitions below its stated threshold, while also defining assumptions and limitations. That is Tide’s account of the system’s security properties; the documentation does not, by itself, establish that deployments meet those assumptions or provide independent certification. TideCloak Threat Model
Rank #2
- Not immunity from all breaches: the phrase does not mean that an application, user account, endpoint or node cannot be attacked.
- Threshold and collusion matter: the protection depends on how many participants an attacker can control and on the configured threshold.
- Availability matters too: distributing authority can make a system dependent on enough nodes being reachable for an operation. The exact recovery and availability behavior must be evaluated for a deployment.
- Independence must be real: organizational separation is useful only if the participants are not effectively controlled by a shared administrator or common failure point.
These are reasons to read Tide’s threat model alongside the architecture description, not to treat the threshold number as a stand-alone guarantee.
What TideCloak is today
Tide’s current documentation presents TideCloak as a Keycloak-based identity and access management service connected to the Tide Cybersecurity Fabric. It describes application integration through standard identity interfaces and SDKs, alongside distributed cryptographic operations. This is a software architecture and developer integration path, rather than evidence of a central physical security appliance. TideCloak introduction
Rank #3
How the documented E2EE integration works
Tide’s E2EE setup guide describes an application workflow based on TideCloak roles, an appropriately licensed Tide realm, Quorum Enforced Authorization and the Tide SDK. The SDK is used for application encryption and decryption. Tide’s E2EE setup guide
- Use a Tide realm with the appropriate license and configure Quorum Enforced Authorization.
- Set up the roles used by the application in TideCloak.
- Integrate the Tide SDK to perform the application’s encryption and decryption workflow.
The guide establishes a documented integration route, but does not on its own establish deployment security, operational performance or suitability for every application. Teams should assess node operators, threshold assumptions, availability and recovery requirements, implementation complexity, and the evidence available for independent review before adopting a system of this kind.
Rank #4
- Ultra-Compact FIDO2 Security Key – Plug-and-stay or carry on a keychain. This USB-C hardware security key offers portable, always-on protection for desktop and mobile use.(Item Size: 0.73 X 0.60 X 0.30 inches)
- USB-C Hardware Key for All Devices – Works with USB-C ports on PC, Mac, Android, and USB-C iPhones. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key – Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey – Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication – Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
What to evaluate before relying on a distributed cryptography service
For a real deployment decision, ask who operates each node and whether those operators are independent; what the threshold means under the threat model; what happens when nodes are unavailable; how recovery is handled; how applications integrate and are audited; and what independent security evaluations exist. Tide’s published materials explain its own design and threat assumptions, but the materials cited here do not establish that Tide outperforms other threshold-cryptography or centralized key-management options.
Quick Recap
Best Value
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

