I just found a weird things on they ToS [1] ... 8. Our service may automatically delete a piece of data you upload or give someone else access to where it determines that that data is an exact duplicate of original data already on our service. In that case, you will access that original data. Duplicate check, I get that. But, how do they do it? They say the files are encrypted on the browser, so if I upload file X an…
The user's javascript that encrypted the file can also make a hash send it to mega, and then they check if they already have that. EDIT: They never get to see your key or what is in the file.
Mega has launched
61–70 of 272 posts
Re: Mega has launched
#62I just found a weird things on they ToS [1] ... 8. Our service may automatically delete a piece of data you upload or give someone else access to where it determines that that data is an exact duplicate of original data already on our service. In that case, you will access that original data. Duplicate check, I get that. But, how do they do it? They say the files are encrypted on the browser, so if I upload file X an…
Re: Mega has launched
#63How exactly does this work, if they don't have access to the original? > 8. Our service may automatically delete a piece of data you upload or give someone else access to where it determines that that data is an exact duplicate of original data already on our service. In that case, you will access that original data.
Re: Mega has launched
#64I just found a weird things on they ToS [1] ... 8. Our service may automatically delete a piece of data you upload or give someone else access to where it determines that that data is an exact duplicate of original data already on our service. In that case, you will access that original data. Duplicate check, I get that. But, how do they do it? They say the files are encrypted on the browser, so if I upload file X an…
Re: Mega has launched
#65The clean interface makes the tagline (lifted from Daft Punk w/o credit) that much more conspicuous. Clearly, some things haven't changed.
Re: Mega has launched
#66Earlier quoted context omitted.
Well, why do you use Safari?
I use it because it supports proper continuous zooming with pinch-to-zoom on a trackpad (exactly like Safari on iOS devices). Chrome does a weird step-by-step increment that seems to involve re-laying out the page at each step. The multi-touch interaction with Safari is just better in general, IMO.
Re: Mega has launched
#67Earlier quoted context omitted.
The user's javascript that encrypted the file can also make a hash send it to mega, and then they check if they already have that. EDIT: They never get to see your key or what is in the file.
Ok, so I try to upload a.exe to Mega. They make a hash, detect someone has already uploaded it. They don't upload my file, and instead they place a link in my account to that "a.exe" of some other user. How can I access it then? Because it's encrypted with a key which is not mine.
Re: Mega has launched
#68Earlier quoted context omitted.
According to the help page, no keys (except the public key) ever leave the client [1]. [1] https://mega.co.nz/#help_security EDIT: The senario in the posts above sound more likely. The exact text of the help is "No usable encryption keys ever leave the client computers (with the exception of RSA public keys)." So they probably store an encrypted version of the keys server side.
In that case if I log in with a different browser, how do I access my stuff? How do other people access my stuff? Doesn't work...
I agree with the sentiment, though, that this is security theater. It's subject to the same problem as Hushmail, where they could be forced to snoop on their customers by modifying client code.
[1] http://arstechnica.com/business/2013/01/mega-arrives-ars-goe...
Re: Mega has launched
#69EDIT:
It's because AJAX return "500 server too busy" error.
Re: Mega has launched
#70"Warning: You are using an outdated browser, which adversely affects your file transfer performance. Please upgrade to Google Chrome." is this a joke? I'm on FF19
File upload didn't work though....