Live data from Hacker News

Wuala: Secure Cloud Storage

wuala.com

141–150 of 207 posts

Re: Wuala: Secure Cloud Storage

#141
post #109

Seriously? Wuala is a service run by LaCie. LaCie is owned by Seagate, an American corporation. It doesn't matter where the servers are, because all the important decisions will be made in Cupertino, California. http://www.lacie.com/us/company/news/news.htm?id=10722 Now, client-side encryption is a much more interesting aspect of their service, but is it worth the trouble if Wuala's clunky client takes 100 times long…

Why not just store a TrueCrypt volume(s) in Dropbox?

This is assuming the Government doesn't force Dropbox to install a keylogger on their client to get users TrueCrypt passphrases and possibly keyfiles.

Re: Wuala: Secure Cloud Storage

#142
post #9

I recently tried replacing Dropbox with Wuala because of privacy concerns. I failed, and in the process realized how successful Dropbox has been in creating an awesome user experience! I'm still looking for a locally encrypted Dropbox-alternative. So if any of you are making one, please speak up :) (Edit) I should specify that it was the user experience that made me give up on Wuala, and any proper Dropbox alternativ…

We have a product coming out soon that's fully open source, self hostable (but also offered as a service), client-encrypted, and backed by Tent.

Mobile API?

Re: Wuala: Secure Cloud Storage

#143
post #9

I recently tried replacing Dropbox with Wuala because of privacy concerns. I failed, and in the process realized how successful Dropbox has been in creating an awesome user experience! I'm still looking for a locally encrypted Dropbox-alternative. So if any of you are making one, please speak up :) (Edit) I should specify that it was the user experience that made me give up on Wuala, and any proper Dropbox alternativ…

We have a product coming out soon that's fully open source, self hostable (but also offered as a service), client-encrypted, and backed by Tent.

[deleted]

Re: Wuala: Secure Cloud Storage

#144
post #9

I recently tried replacing Dropbox with Wuala because of privacy concerns. I failed, and in the process realized how successful Dropbox has been in creating an awesome user experience! I'm still looking for a locally encrypted Dropbox-alternative. So if any of you are making one, please speak up :) (Edit) I should specify that it was the user experience that made me give up on Wuala, and any proper Dropbox alternativ…

On my "somebody should create this, and I might eventually" list is an open source, P2P, optionally server-backed, encrypted Dropbox replacement. Bittorrent's Sync almost gets there, but isn't open source. I haven't really looked at it, but ownCloud might do what I want.

Wuala used to be P2P (host other people's files to get more space for your files) until LaCie bought it.

Re: Wuala: Secure Cloud Storage

#145

Earlier quoted context omitted.

Nobody sane wants software to auto-update, especially not security-relevant software. This is in particular true if you reviewed the source code of the software at one point in time. Furthermore, for the software to be able to even auto-update, it would have to be able to change its own binary. I don’t know how this particular piece of software works, but it is possible to run FUSE ‘drivers’ as a user on Linux, with…

From http://www.wuala.com/en/download/linux : > The package installs Wuala and registers our repository for further updates. This is even more harmful that it sounds, as someone who has repo access (be it some evil staff member or, more possibly, inturder) may push not only malicious Wuala build, but any package with higher version number than in other repos (say, a linux-image-999.999 with a bundled rootkit) and if…

That is not really auto-update (only if you enabled it system-wide) – and after reviewing the source code, which is necessary anyhow to make sure it is actually ‘secure’, you would then remove the file in /etc/apt/sources.list.d and be happy :-)

Re: Wuala: Secure Cloud Storage

#146
post #96

Hello there, Gianluca from Wuala here. First, this is how Wuala works: You as an user place a file in the client. The file gets encrypted (including using your password and username) and then gets uploaded and split into different pieces. We are currently using AES-256 for encryption (and RSA 2048 fpr signature and key exchange when sharing a folder and SHA-256 for integrity checks). The password does NOT get transmi…

Hi Gianluca, What about when files/folders are shared? Is encryption dropped so anybody with a link can have access?

Re: Wuala: Secure Cloud Storage

#147
post #142

Earlier quoted context omitted.

We have a product coming out soon that's fully open source, self hostable (but also offered as a service), client-encrypted, and backed by Tent.

Mobile API?

It's powered by the Tent protocol (https://tent.io) so by definition, yes. The library is also open for anyone who wants to implement their own alternative, compatible apps, and alternative compatible libraries could be implemented since it's all just specific (documented) types of Tent posts.

Re: Wuala: Secure Cloud Storage

#148
post #72

So honest question, but how is having your data stored in Switzerland (where Wuala is based) any different than having it in the US? Or is it just the promise of local encryption that makes it safer? Some purported info about data protection for Switzerland: http://www.dataprotection.ch/en/disclosing-personal-data.asp > Restrictions on disclosure The DPA does not permit the disclosure of sensitive data or personality…

(Post above mentions that LaCie is owned by the American Corporation Seagate.)

Re: Wuala: Secure Cloud Storage

#149
post #109

Seriously? Wuala is a service run by LaCie. LaCie is owned by Seagate, an American corporation. It doesn't matter where the servers are, because all the important decisions will be made in Cupertino, California. http://www.lacie.com/us/company/news/news.htm?id=10722 Now, client-side encryption is a much more interesting aspect of their service, but is it worth the trouble if Wuala's clunky client takes 100 times long…

Why not just store a TrueCrypt volume(s) in Dropbox?

That's what I do, I have a small (100 MB) small volume sync in my DB, works like a charm :)

Re: Wuala: Secure Cloud Storage

#150

For what it's worth, what you need is: -- a company with no connections to the United States. Ideally, it should be privately owned by a foreign individual known for strong privacy views and who has promised never to sell. -- local encryption -- open source ("trust but verify") -- actually works Wuala, from the comments here, meets only one of those four requirements.

Uh, just one? The way I count it's 2.5 out of 4.

It's a Swiss company, owned by LaCie (French) which is again owned by Seagate (US). So I would say that's half a point.

Data is en-/decrypted locally. There's a reason they don't have a web interface, but require you to use the client.

It's indeed not open source. Would be nice if it was.

And it actually does work. There's room for improvement (isn't there always?), but in my experience it's working well.

Post reply on HN