Live data from Hacker News

SpiderOakONE – Zero Knowledge Cloud Storage

spideroak.com

51–60 of 93 posts

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#51
post #45

Earlier quoted context omitted.

SpiderOak founder here... A few cryptographers have noticed SpiderOak's marketing term Zero Knowledge is inconsistent with the academic definition. Maybe it doesn't mean what we think it means[1]? SpiderOak was one of the first companies to use this phrase commercially and the need has only grown stronger. At the heart of the issue is the difficulty for end users to decipher the terms cloud vendors use to describe th…

I really want to give you guys money, but can't trust you without having client and server side source. I need client side source so third parties can freely audit your work. I need server side source so I can store my data at some random colo and wrap the rack in tinfoil (more realisitcally, so I know I can just switch providers if you are out of business in ten years). Have you considered licensing your stuff using…

Thank you for your interest in SpiderOak and valuing work to improve the choices available that preserve privacy.

For what it's worth, everything we've built since 2008 has published source code. Most recently that's Semaphor[1], which is written in Go and React.

I think it's very important that products have what Zooko calls an "economic feedback loop" to be successful. As just one example, volunteer projects rarely have staff that do the grinding but necessary work of testing that each release works well on every version of all support operating systems and platforms, because it isn't fun. I think this is why although some teams publish their client source code, very few service providers publish their server source code. It would make it too easy for competitors to emerge and undercut on price while giving little back (the biggest cost is the often the development work itself.)

That said, we've been in business for 10 years and are not going away! Thanks for your feedback.

[1] https://spideroak.com/solutions/semaphor/business/tour

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#52
post #13
post #10

Spider Oak - Please stop describing your service as "Zero Knowledge" unless and until you deploy a service that is actually is. E2E encryption great, but it is not the same thing.

In cryptography, "zero knowledge" means something very different than "service providers cannot access cleartext data". > In cryptography, a zero-knowledge proof or zero-knowledge protocol is a method by which one party (the prover) can prove to another party (the verifier) that a given statement is true, without conveying any information apart from the fact that the statement is indeed true. source: https://en.wikip…

A lot of customers are going to assume that zero knowledge means no cleartext data is ever stored. I assumed it, and I'm no newbie.

This seems to be an abuse of the motte and bailey kind: they use a word which everyone believes means one thing, but when questioned they resort to a less commok definition because they 'didn't mean it that way.'

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#53
post #28

Earlier quoted context omitted.

The issue is not you vs. other companies; it's you vs 25+ years of cryptographic literature. > no company has yet been shameless enough to deceptively use the term Zero Knowledge. Except you guys? Why use the phrase "zero knowledge" when you fully know that it has a predefined meaning? Call it no information, no leakage, zero leakage, whatever, but why the one term that is already used to refer to a different concept…

A lot of words are overloaded, across domains as well as within domains, that is not ideal but also no unsurmountable problem, you can always clarify your usage by providing definitions. There is certainly not much of a point to explain things in precise and correct terminology if this prevents the intended audience from understanding you. On the other hand, people aware of the technical details will have no big diff…

This particular term is not overloaded. People familiar with encryption know it to mean something specific.

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#54
post #10

Spider Oak - Please stop describing your service as "Zero Knowledge" unless and until you deploy a service that is actually is. E2E encryption great, but it is not the same thing.

SpiderOak founder here... A few cryptographers have noticed SpiderOak's marketing term Zero Knowledge is inconsistent with the academic definition. Maybe it doesn't mean what we think it means[1]? SpiderOak was one of the first companies to use this phrase commercially and the need has only grown stronger. At the heart of the issue is the difficulty for end users to decipher the terms cloud vendors use to describe th…

Since you're speaking the language of product marketing, which is one I sort of speak too, can I gingerly offer you some advice?

Until you come up with some other cool-sounding term for end-to-end encrypted storage, every time your product is discussed in a forum that includes people familiar with cryptography, the discussion is going to be dominated with threads about how your product doesn't do what its name claims it does.

If it were me, I would think of this as a very suboptimal situation; sort of the worst case for what a product name can do.

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#55

@rarrrrrr - Do you have a more precise timeline of when the SpiderOak Notes App will be launched in 2017? Would love to try it out as I'm getting tired of various issues w/ Evernote and haven't been able to find a good alternative yet.

Thanks for asking! I'm really excited about a ZK note app! We haven't yet determined the priority of this vs. other projects in 2017. If you haven't already, please signal your interest below[1]. So far it is a prototype, although it is based on the already proven code used in Semaphor[2], our encrypted group chat and file sharing application, so it's "just" a bunch of UI work now :-) [1] https://spideroak.com/about/…

At this moment I'm a paying user of both Evernote and Dropbox and I do not like how they are focusing on extra bells&whistles instead of investing time in their encryption methods to make my data more safe.

From a business perspective you can get the money that I give to Evernote and Dropbox if Spideroak offers competing products. And for me the advantage is that my data is more secure because of the zero knowledge(1) idea and I do not need to worry about wild ideas from companies think about employees reading my notes "to make my experience better". Yes I'm looking at you Evernote.

(1) until 10 minutes ago I did not know that zero knowledge had a specific technical meaning that is different than what Spideroak implements. And I even have Bruce Schneiers Applied Cryptography on my bookself. I'll need to read that again. Maybe it should be called "Full stack encryption" because it covers everything from data transport, to storage, to metadata encryption, etc...

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#56
post #45

Earlier quoted context omitted.

I really want to give you guys money, but can't trust you without having client and server side source. I need client side source so third parties can freely audit your work. I need server side source so I can store my data at some random colo and wrap the rack in tinfoil (more realisitcally, so I know I can just switch providers if you are out of business in ten years). Have you considered licensing your stuff using…

Thank you for your interest in SpiderOak and valuing work to improve the choices available that preserve privacy. For what it's worth, everything we've built since 2008 has published source code. Most recently that's Semaphor[1], which is written in Go and React. I think it's very important that products have what Zooko calls an "economic feedback loop" to be successful. As just one example, volunteer projects rarely…

I'm sympathetic to the economic feedback problem you're describing. I think the BSL addresses the concern about undercutting. Sure, people could pirate your software, but short of that, it probably makes more sense to implement from scratch than either wait ten years, or fork code that is ten years old, which is all your competitors could do with the source. Honestly, I would probably just pay for your service after spending a few hours spot checking the source.

Anyway, I'd love to hear your thoughts on the licensing model, even if you're not considering it at spideroak.

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#59

Earlier quoted context omitted.

The issue is not you vs. other companies; it's you vs 25+ years of cryptographic literature. > no company has yet been shameless enough to deceptively use the term Zero Knowledge. Except you guys? Why use the phrase "zero knowledge" when you fully know that it has a predefined meaning? Call it no information, no leakage, zero leakage, whatever, but why the one term that is already used to refer to a different concept…

Thanks for the feedback. For what it's worth, we did try a bunch of alternative wordings, and Zero Knowledge was the phrase that non technologists found most accessible. We prioritized making the explanation clear to non-experts vs. to the community of cryptographers.

I'd like to propose "Zero Access", as in zero access to the plaintext.

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#60

Earlier quoted context omitted.

I tried spider oak a while ago, and I thought it was horrible in terms of ui, performance and bloat. I'm assuming they didn't change their stack/devs, so I will not even try this one.

I find that surprsing. I've been using SpiderOak for years without noticing any bloat or performance issues with the background service. On the contrary, I was often surprised how little space I'm using in spite of the fact that they store multiple versions of my files. It doesn't hog memory or bandwidth or CPU at all. The UI is indeed a bit weird and its performance can be erratic sometimes, but it gets the job done…

I used to be a paying customer (years ago, things may be better now), and I had many issues with CPU getting stuck at 100% for long stretches of time, or uploads/downloads would transfer a bunch of data, or would be slow, things like that.

Then, one day, my account got full, and I couldn't delete anything unless I got some more free space first (see the problem?). I believe support gave me a few extra GB just for the deletion, but that didn't work either and I decided to stop using the whole thing. That's when I switched to attic/borg, which is much superior for my use case (backups).

Post reply on HN