Live data from Hacker News

SpiderOakONE – Zero Knowledge Cloud Storage

spideroak.com

11–20 of 93 posts

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#11

In addition to not being (fully) open source, something that also should be mentioned is, that if u use the mobile apps it unfortunately still isn't "zero knowledge" [0]. [0] https://spideroak.com/manual/spideroak-on-mobile

Until recently, mobile platforms were not capable of doing the on-device encryption necessary for SpiderOak's Zero Knowledge implementation.

Anyone any idea what the issue is or was? What would prevents you from doing PBKDF2, RSA and AES [1] on a mobile device?

[1] https://spideroak.com/manual/zero-knowledge-explained

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#12
post #10

Spider Oak - Please stop describing your service as "Zero Knowledge" unless and until you deploy a service that is actually is. E2E encryption great, but it is not the same thing.

Following to their architectural design, they do not get access to any encryption key and no key leaves user device in unprotected form. Is not this enough to be advertised as "zero-knowledge" service provider?

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#13
post #10

Spider Oak - Please stop describing your service as "Zero Knowledge" unless and until you deploy a service that is actually is. E2E encryption great, but it is not the same thing.

In cryptography, "zero knowledge" means something very different than "service providers cannot access cleartext data".

> In cryptography, a zero-knowledge proof or zero-knowledge protocol is a method by which one party (the prover) can prove to another party (the verifier) that a given statement is true, without conveying any information apart from the fact that the statement is indeed true.

source: https://en.wikipedia.org/wiki/Zero-knowledge_proof

z.cash is a zero knowledge system and has a good definition of it on its FAQ:

> Zero knowledge proofs are a scientific breakthrough in the field of cryptography: they allow you to prove knowledge of some facts about hidden information without revealing that information. The property of allowing both verifiability and privacy of data makes for a strong use case in all kinds of transactions, and we’re integrating this concept into a block chain for encrypting the sender address, the recipient address, and the amount. A block chain that encrypts transaction data (making it private) and lacks zero-knowledge proofs also lacks the assurance that all the transactions are valid. This is because the nodes in the network can’t determine whether the sender really had that money or whether they previously sent it to someone else, or never had it in the first place. The encrypted data becomes unverifiable by network nodes.

source: https://z.cash/support/faq.html?page=0

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#14
post #10

Spider Oak - Please stop describing your service as "Zero Knowledge" unless and until you deploy a service that is actually is. E2E encryption great, but it is not the same thing.

Following to their architectural design, they do not get access to any encryption key and no key leaves user device in unprotected form. Is not this enough to be advertised as "zero-knowledge" service provider?

No, that's called end-to-end or client-side encryption. Zero-knowledge is a property of a certain class of methods that allow one party to prove to another that a certain statement is true, without revealing anything else about it.

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#15
post #10

Spider Oak - Please stop describing your service as "Zero Knowledge" unless and until you deploy a service that is actually is. E2E encryption great, but it is not the same thing.

Following to their architectural design, they do not get access to any encryption key and no key leaves user device in unprotected form. Is not this enough to be advertised as "zero-knowledge" service provider?

The term "zero knowledge" has a specific technical meaning in cryptography: https://en.wikipedia.org/wiki/Zero-knowledge_proof

Passing encrypted data through a storage device isn't a "zero-knowledge protocol" in a cryptographic sense, it's just normal cryptography.

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#16
post #10

Spider Oak - Please stop describing your service as "Zero Knowledge" unless and until you deploy a service that is actually is. E2E encryption great, but it is not the same thing.

SpiderOak founder here...

A few cryptographers have noticed SpiderOak's marketing term Zero Knowledge is inconsistent with the academic definition. Maybe it doesn't mean what we think it means[1]? SpiderOak was one of the first companies to use this phrase commercially and the need has only grown stronger.

At the heart of the issue is the difficulty for end users to decipher the terms cloud vendors use to describe their security. Doing so would require discrimination between transport encryption, data encryption, meta data encryption, encryption at rest vs. in motion, and then most importantly evaluate key management and access. This vocabulary is foreign to most folks. Vendors often exploit the inaccessibility of these topics to make a series of statements that, while often factually correct individually, together create a false sense of privacy.

SpiderOak launched a online backup product for Linux, Mac, and Windows in 2007. The competitors were companies like Xdrive, Mozy, Carbonite and SugarSync. Each claimed that customer data was fully encrypted. Even the most credible journalists writing for well funded publications with fact checking budgets were fooled and repeated these misleading claims to end users. [2]

In 2009 when Dropbox launched, they made misleading claims about the encryption of customer files and their internal ability to access customer's data or provide that data to 3rd parties, leading to a well publicized FTC deceptive trade practices complaint. [3] The deception had been so effective that leading software engineers were shocked to discover Dropbox had full access to the data they had stored online. [4]

In response to customer requests on one of their forums, Mozy explained why it would be "impossible" for a storage service to protect users' privacy by encrypting the file and folder names customers store in a way Mozy could not read. SpiderOak customers had benefited from the impossible for years.

Recently Slack made the unbelievable claim on Twitter that their service includes end to end encryption (it doesn't.) Perhaps they mean from your end to their end?

Lately there's a new phrase "customer managed keys" used by cloud providers, which sounds really great, but is typically just elaborate hand waving that ultimately allows the vendor and their staff the same level of data access as if it were not encrypted.

In 2007 we found ourselves frequently explaining "we don't know the names of your files, the names of your folders, the date they were created or last modified or accessed, their size, their checksums or hashes... in short we know nothing about your data except how much you store." We started using the phrase Zero Knowledge as a headline to this long explanation.

It's important to recognize that cryptographers already understand encryption and the terminology is intended for everyday folks. When I'm speaking with a technologist about how SpiderOak products work, I would typically use the phrase end to end encryption.

If we want to end mass surveillance, the only way this can happen is through viral adoption of end to end encrypted products and services. Great UX, education, and terminology are powerful tools, and unlike phrases involving the word "encryption", to my knowledge no company has yet been shameless enough to deceptively use the term Zero Knowledge.

[1] https://www.youtube.com/watch?v=G2y8Sx4B2Sk

[2] http://allthingsd.com/20080403/sugarsync-offers-the-best-met...

[3] https://www.wired.com/2011/05/dropbox-ftc/

[4] http://tirania.org/blog/archive/2011/Apr-19.html

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#17
post #10

Spider Oak - Please stop describing your service as "Zero Knowledge" unless and until you deploy a service that is actually is. E2E encryption great, but it is not the same thing.

Following to their architectural design, they do not get access to any encryption key and no key leaves user device in unprotected form. Is not this enough to be advertised as "zero-knowledge" service provider?

As a technical term zero-knowledge has a very specific meaning [1] and is not what they are using. Here it is just a marketing term and may confuse people knowing about the technical meaning but that is certainly only a very small fraction of the population and so it is probably not a huge issue.

[1] https://en.wikipedia.org/wiki/Zero-knowledge_proof

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#18
post #10

Spider Oak - Please stop describing your service as "Zero Knowledge" unless and until you deploy a service that is actually is. E2E encryption great, but it is not the same thing.

SpiderOak founder here... A few cryptographers have noticed SpiderOak's marketing term Zero Knowledge is inconsistent with the academic definition. Maybe it doesn't mean what we think it means[1]? SpiderOak was one of the first companies to use this phrase commercially and the need has only grown stronger. At the heart of the issue is the difficulty for end users to decipher the terms cloud vendors use to describe th…

The issue is not you vs. other companies; it's you vs 25+ years of cryptographic literature.

> no company has yet been shameless enough to deceptively use the term Zero Knowledge.

Except you guys? Why use the phrase "zero knowledge" when you fully know that it has a predefined meaning? Call it no information, no leakage, zero leakage, whatever, but why the one term that is already used to refer to a different concept?

I get that it's a sexy name, but that's why cryptographers use it to refer to a much cooler concept than mere encryption.

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#19
post #11

In addition to not being (fully) open source, something that also should be mentioned is, that if u use the mobile apps it unfortunately still isn't "zero knowledge" [0]. [0] https://spideroak.com/manual/spideroak-on-mobile

Until recently, mobile platforms were not capable of doing the on-device encryption necessary for SpiderOak's Zero Knowledge implementation. Anyone any idea what the issue is or was? What would prevents you from doing PBKDF2, RSA and AES [1] on a mobile device? [1] https://spideroak.com/manual/zero-knowledge-explained

It's mostly that the desktop app is Python and C, and there wasn't a clear path to make that same code base run on mobile, so the mobile app is just a reader.

However for Semaphor, our encrypted group chat and file sharing tool (akin to IRC, to Slack or HipChat) the internals are written in Go and it's the same code base on all platforms, including mobile. That source code is also published for security review. We plan to migrate SpiderOakONE to use that same stack so the mobile experience is the same as desktop.

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#20

Earlier quoted context omitted.

SpiderOak founder here... A few cryptographers have noticed SpiderOak's marketing term Zero Knowledge is inconsistent with the academic definition. Maybe it doesn't mean what we think it means[1]? SpiderOak was one of the first companies to use this phrase commercially and the need has only grown stronger. At the heart of the issue is the difficulty for end users to decipher the terms cloud vendors use to describe th…

The issue is not you vs. other companies; it's you vs 25+ years of cryptographic literature. > no company has yet been shameless enough to deceptively use the term Zero Knowledge. Except you guys? Why use the phrase "zero knowledge" when you fully know that it has a predefined meaning? Call it no information, no leakage, zero leakage, whatever, but why the one term that is already used to refer to a different concept…

Thanks for the feedback. For what it's worth, we did try a bunch of alternative wordings, and Zero Knowledge was the phrase that non technologists found most accessible.

We prioritized making the explanation clear to non-experts vs. to the community of cryptographers.

Post reply on HN