One of the points not mentioned in the article is that this analysis is useful even if (like me, tptacek, and many others) you don't trust Javascript crypto. That's because Mega is designed as simply an API that any client (including one distributed as a desktop application) could implement. However, another client implementing this same spec would have the same weaknesses. It's important that we get the design impro…
Paying customer here, thank you for a wonderful product and service! One question I have is why SpiderOak client is not open-source? As I understand, it is Python and decompiling it for analysis is not too much trouble, but still...
I should also note that the crypto code in SpiderOak is in one specific module, and we have repeatedly paid for careful audits of that code.
Lastly, we have a new crypto product in the works which we will announce at RSA in February, which is 100% open source, and of particular interest to developers in addition to SpiderOak customers. Please stay tuned!