Live data from Hacker News

SpiderOakONE – Zero Knowledge Cloud Storage

spideroak.com

61–70 of 93 posts

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#61
post #50

I really want to use this, but the mobile app (Android) really lacks very basic functionality - uploading files. I recently stopped renewing my Dropbox on an annual license and will switch once I find a good alternative..

The thing that keeps me on dropbox is the price. I can't find a provider of raw storage that charges less.

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#62

I don't have a ton of data in Dropbox but it's large and growing. Any word if they're going to hook up a "import from Box/Dropbox" feature here?

SpiderOak can backup and sync arbitrary folders (including external drives, network volumes, etc.) So one migration path is just to select the Dropbox folder for backup by SpiderOak. (Or just move data from Dropbox folder to the SpiderOak Hive folder.)

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#63
post #54

Earlier quoted context omitted.

SpiderOak founder here... A few cryptographers have noticed SpiderOak's marketing term Zero Knowledge is inconsistent with the academic definition. Maybe it doesn't mean what we think it means[1]? SpiderOak was one of the first companies to use this phrase commercially and the need has only grown stronger. At the heart of the issue is the difficulty for end users to decipher the terms cloud vendors use to describe th…

Since you're speaking the language of product marketing, which is one I sort of speak too, can I gingerly offer you some advice? Until you come up with some other cool-sounding term for end-to-end encrypted storage, every time your product is discussed in a forum that includes people familiar with cryptography, the discussion is going to be dominated with threads about how your product doesn't do what its name claims…

Unless your target audience is not people who read such forums.

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#64
post #17

Earlier quoted context omitted.

As a technical term zero-knowledge has a very specific meaning [1] and is not what they are using. Here it is just a marketing term and may confuse people knowing about the technical meaning but that is certainly only a very small fraction of the population and so it is probably not a huge issue. [1] https://en.wikipedia.org/wiki/Zero-knowledge_proof

Your link is for zero-knowledge proof. They aren't claiming anything in the realm of proofs, zero-knowledge or not. If "zero-knowledge" implicitly meant "zero-knowledge proof", there would be no reason to ever use the latter phrase. Zero-knowledge is an adjective. It's a modifier. It's the "proof" part in "zero-knowledge proof" that's important in describing what it is. "Zero-knowledge" is a property of the method em…

Not sure whether I was clear enough, but I understand both sides of the argument. It is a very specific technical term and the zero-knowledge proof Wikipedia article states that zero-knowledge is the name of one of three properties that zero-knowledge proof have to satisfy, on the other hand it is also a nice, catchy and probably understandable marketing term if you want to express that you know (almost) nothing about the users' data.

Developer me would certainly prefer technical accuracy but we all know that users certainly could not care less what is the technically correct name for the thing. So I don't care at all whether they call it zero-knowledge or not, they are not trying to trick anybody into believing they are doing zero-knowledge stuff in the cryptographic sense. I actually like zero-trust but I can see how this could easily be interpreted in the wrong way, should or must not be trusted instead of need not be trusted.

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#65

Earlier quoted context omitted.

Thanks for the feedback. For what it's worth, we did try a bunch of alternative wordings, and Zero Knowledge was the phrase that non technologists found most accessible. We prioritized making the explanation clear to non-experts vs. to the community of cryptographers.

I'd like to propose "Zero Access", as in zero access to the plaintext.

That's actually not bad. I was fine with SpiderOak going for a term that is simple, catchy, and easy to market. Zero Access is the kind of alternative that might work. That specific one might have a problem: send perception of user having zero access to their own data when most clouds constantly reinforce "access from anywhere any time."

You're thinking along the right lines. I think variations of the words safe and vault have worked for other companies, too, given people understand what they do. "Your data is in a locked vault that we hold for you while you keep the keys or combination." That sort of thing.

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#66
post #63
post #54

Earlier quoted context omitted.

Since you're speaking the language of product marketing, which is one I sort of speak too, can I gingerly offer you some advice? Until you come up with some other cool-sounding term for end-to-end encrypted storage, every time your product is discussed in a forum that includes people familiar with cryptography, the discussion is going to be dominated with threads about how your product doesn't do what its name claims…

Unless your target audience is not people who read such forums.

Exactly. The obvious counterpoint. Those people aren't buying shit from them and represent basically no market share. It's privacy-conscious users of services like DropBox they're going after. Most of them don't know crypto or a lot of terms people suggested here. Marketing wisdom dictates you call it whatever gets them to see its value & buy it. Then ignore the haters as you roll around in cash.

Business 101 if goal is max adoption & profit.

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#67
post #45

Earlier quoted context omitted.

SpiderOak founder here... A few cryptographers have noticed SpiderOak's marketing term Zero Knowledge is inconsistent with the academic definition. Maybe it doesn't mean what we think it means[1]? SpiderOak was one of the first companies to use this phrase commercially and the need has only grown stronger. At the heart of the issue is the difficulty for end users to decipher the terms cloud vendors use to describe th…

I really want to give you guys money, but can't trust you without having client and server side source. I need client side source so third parties can freely audit your work. I need server side source so I can store my data at some random colo and wrap the rack in tinfoil (more realisitcally, so I know I can just switch providers if you are out of business in ten years). Have you considered licensing your stuff using…

Is open source really required? We at Haystack Software make a backup app (Arq) with client-side encryption that doesn't require any server side code (it supports a number of cloud providers' APIs). We don't publish the app's source, but the data format is open/documented, the data go in your cloud account, and you can monitor network traffic from it to ensure it's not connecting to us or anyplace unwanted. Your data don't come to us at all -- they're sent to your cloud account.

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#69

Earlier quoted context omitted.

SpiderOak founder here... A few cryptographers have noticed SpiderOak's marketing term Zero Knowledge is inconsistent with the academic definition. Maybe it doesn't mean what we think it means[1]? SpiderOak was one of the first companies to use this phrase commercially and the need has only grown stronger. At the heart of the issue is the difficulty for end users to decipher the terms cloud vendors use to describe th…

The issue is not you vs. other companies; it's you vs 25+ years of cryptographic literature. > no company has yet been shameless enough to deceptively use the term Zero Knowledge. Except you guys? Why use the phrase "zero knowledge" when you fully know that it has a predefined meaning? Call it no information, no leakage, zero leakage, whatever, but why the one term that is already used to refer to a different concept…

This happens all the time with marketing, surely this is not the first time you have seen a company co opt a term for marketing purposes.

This seems like a case of perfect being the enemy of good.

Re: SpiderOakONE – Zero Knowledge Cloud Storage

#70
post #10

Spider Oak - Please stop describing your service as "Zero Knowledge" unless and until you deploy a service that is actually is. E2E encryption great, but it is not the same thing.

SpiderOak founder here... A few cryptographers have noticed SpiderOak's marketing term Zero Knowledge is inconsistent with the academic definition. Maybe it doesn't mean what we think it means[1]? SpiderOak was one of the first companies to use this phrase commercially and the need has only grown stronger. At the heart of the issue is the difficulty for end users to decipher the terms cloud vendors use to describe th…

> If we want to end mass surveillance, the only way this can happen is through viral adoption of end to end encrypted products and services.

I strongly disagree. The "only" way mass surveillance will end is when is made illegal and the entities that practice it are treated as pariahs by civilized humanity.

It is purely a political issue.

Post reply on HN