Live data from Hacker News

SpiderOakONE – Zero Knowledge Cloud Storage

spideroak.com

21–30 of 93 posts

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#21
post #10

Spider Oak - Please stop describing your service as "Zero Knowledge" unless and until you deploy a service that is actually is. E2E encryption great, but it is not the same thing.

SpiderOak founder here... A few cryptographers have noticed SpiderOak's marketing term Zero Knowledge is inconsistent with the academic definition. Maybe it doesn't mean what we think it means[1]? SpiderOak was one of the first companies to use this phrase commercially and the need has only grown stronger. At the heart of the issue is the difficulty for end users to decipher the terms cloud vendors use to describe th…

I don't think you have to be a cryptographer to notice this and it makes you sound likes snake-oil salesmen even if you aren't. The misuse of 'zero knowledge' doesn't seem any clearer to non-technical users but it does a good job of confusing the sort of people you want recommending your product.

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#22
post #2

They've been around for a while and are highly regarded. The one thing that makes their privacy weak is: The software involved in the encryption/password handling is not open source. We have only their word for it that they are not snooping or letting anyone else snoop. If you're willing to do the extra work, you can get a cloud service like Dream Objects, and use software like duply/duplicity to store your files onl…

I tried spider oak a while ago, and I thought it was horrible in terms of ui, performance and bloat. I'm assuming they didn't change their stack/devs, so I will not even try this one.

Thanks for the feedback. Sorry it didn't work out for you.

FYI, the SpiderOakONE app and the backend storage service received a refresh in 2016, and another one is underway right now (now all needed libraries are Python3 compatible!)

The existing UI is oriented toward power users, and is a bit complex for most people. The upcoming refresh simplifies many things while retaining the flexibility under "advanced" settings.

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#23
post #10

Spider Oak - Please stop describing your service as "Zero Knowledge" unless and until you deploy a service that is actually is. E2E encryption great, but it is not the same thing.

SpiderOak founder here... A few cryptographers have noticed SpiderOak's marketing term Zero Knowledge is inconsistent with the academic definition. Maybe it doesn't mean what we think it means[1]? SpiderOak was one of the first companies to use this phrase commercially and the need has only grown stronger. At the heart of the issue is the difficulty for end users to decipher the terms cloud vendors use to describe th…

Thank you for the clarification. I really appreciate all the hard work you guys do in trying to combat unwarranted breaches of privacy.

I've had my reservations about companies that make such bold claims as yours but I will look into your platform more and give the free trial a whirl.

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#24
post #21

Earlier quoted context omitted.

SpiderOak founder here... A few cryptographers have noticed SpiderOak's marketing term Zero Knowledge is inconsistent with the academic definition. Maybe it doesn't mean what we think it means[1]? SpiderOak was one of the first companies to use this phrase commercially and the need has only grown stronger. At the heart of the issue is the difficulty for end users to decipher the terms cloud vendors use to describe th…

I don't think you have to be a cryptographer to notice this and it makes you sound likes snake-oil salesmen even if you aren't. The misuse of 'zero knowledge' doesn't seem any clearer to non-technical users but it does a good job of confusing the sort of people you want recommending your product.

Thank you. I'm all for switching if we can find a phrase that's accessible to non technical people.

Ideally it would be a phrase that's adopted by many sites, the press, etc. (as Zero Knowledge has been, for better or worse.) It should accurately convey the situation that 1) the data is meaningfully encrypted 2) the meta data is meaningfully encrypted and 3) only the customer has access to the encryption keys.

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#25
post #10

Spider Oak - Please stop describing your service as "Zero Knowledge" unless and until you deploy a service that is actually is. E2E encryption great, but it is not the same thing.

SpiderOak founder here... A few cryptographers have noticed SpiderOak's marketing term Zero Knowledge is inconsistent with the academic definition. Maybe it doesn't mean what we think it means[1]? SpiderOak was one of the first companies to use this phrase commercially and the need has only grown stronger. At the heart of the issue is the difficulty for end users to decipher the terms cloud vendors use to describe th…

This came up in a previous thread (can't find atm) and I suggested alternate, more cryptographically correct terms: "provider-obscured" and "homomorphic" (this is like homomorphic encryption, but where the only operation allowed is retrieval).

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#27
post #2

They've been around for a while and are highly regarded. The one thing that makes their privacy weak is: The software involved in the encryption/password handling is not open source. We have only their word for it that they are not snooping or letting anyone else snoop. If you're willing to do the extra work, you can get a cloud service like Dream Objects, and use software like duply/duplicity to store your files onl…

I tried spider oak a while ago, and I thought it was horrible in terms of ui, performance and bloat. I'm assuming they didn't change their stack/devs, so I will not even try this one.

I find that surprsing.

I've been using SpiderOak for years without noticing any bloat or performance issues with the background service. On the contrary, I was often surprised how little space I'm using in spite of the fact that they store multiple versions of my files. It doesn't hog memory or bandwidth or CPU at all.

The UI is indeed a bit weird and its performance can be erratic sometimes, but it gets the job done and has a lot of useful features.

Most importantly, SpiderOak has reliably protected me from losing data and I don't have to babysit it. It just works.

(I'm a happy paying customer. No affiliation with them whatsoever)

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#28

Earlier quoted context omitted.

SpiderOak founder here... A few cryptographers have noticed SpiderOak's marketing term Zero Knowledge is inconsistent with the academic definition. Maybe it doesn't mean what we think it means[1]? SpiderOak was one of the first companies to use this phrase commercially and the need has only grown stronger. At the heart of the issue is the difficulty for end users to decipher the terms cloud vendors use to describe th…

The issue is not you vs. other companies; it's you vs 25+ years of cryptographic literature. > no company has yet been shameless enough to deceptively use the term Zero Knowledge. Except you guys? Why use the phrase "zero knowledge" when you fully know that it has a predefined meaning? Call it no information, no leakage, zero leakage, whatever, but why the one term that is already used to refer to a different concept…

A lot of words are overloaded, across domains as well as within domains, that is not ideal but also no unsurmountable problem, you can always clarify your usage by providing definitions. There is certainly not much of a point to explain things in precise and correct terminology if this prevents the intended audience from understanding you. On the other hand, people aware of the technical details will have no big difficulties to understand something despite simplifications or inaccurate terminology.

I am actually not even sure whether zero-knowledge is not technically correct here. Terms like zero-knowledge proof or zero-knowledge protocol have very specific meanings and certainly do not apply here, but is zero-knowledge on its own really used for something more specific or other than not leaking knowledge? I also immediately thought of zero-knowledge proofs and protocols but nothing like that is mentioned anywhere, at least as far as I can tell, so it was kind if my mistake to read something into it that was not actually there.

EDIT: Zero-knowledge seems to indeed have a very specific technical meaning on its own [1], at least in the context of zero-knowledge proofs.

[1] https://en.wikipedia.org/wiki/Zero-knowledge_proof#Definitio...

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#29
post #2

They've been around for a while and are highly regarded. The one thing that makes their privacy weak is: The software involved in the encryption/password handling is not open source. We have only their word for it that they are not snooping or letting anyone else snoop. If you're willing to do the extra work, you can get a cloud service like Dream Objects, and use software like duply/duplicity to store your files onl…

"If you're willing to do the extra work, you can get a cloud service like Dream Objects, and use software like duply/duplicity to store your files online and encrypted. You may lose some flexibility, though."

I encourage you to look into borg backup[1][2] which appears to have replaced duplicity as the de facto standard for "robust backups that the provider knows nothing about".

This is really the direction you look for providers[3] to go in - giving you a blank slate to write whatever bits you want to and allowing you to control the encryption with your own tools.

If you point borg (or duplicity) at even the most privacy-antagonistic provider, they still have nothing but gibberish.

[1] https://borgbackup.readthedocs.io/en/stable/

[2] https://www.stavros.io/posts/holy-grail-backups/

[3] http://www.rsync.net/products/attic.html

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#30
post #10

Spider Oak - Please stop describing your service as "Zero Knowledge" unless and until you deploy a service that is actually is. E2E encryption great, but it is not the same thing.

SpiderOak founder here... A few cryptographers have noticed SpiderOak's marketing term Zero Knowledge is inconsistent with the academic definition. Maybe it doesn't mean what we think it means[1]? SpiderOak was one of the first companies to use this phrase commercially and the need has only grown stronger. At the heart of the issue is the difficulty for end users to decipher the terms cloud vendors use to describe th…

"Doing so would require discrimination between transport encryption, data encryption, meta data encryption, encryption at rest vs. in motion"

...

"This vocabulary is foreign to most folks."

Please, please keep taking these customers. Can we send you leads directly from our pre-sales inbox ?

"If we want to end mass surveillance, the only way this can happen is through viral adoption of end to end encrypted products and services."

Actually, what we need to do is throw some money at the guy writing borg[1][2]. Or maybe sponsor a code audit. I think I am going to put that on our to-do list for this spring ...

[1] https://borgbackup.readthedocs.io/en/stable/

[2] https://www.stavros.io/posts/holy-grail-backups/

Post reply on HN