Why I'm saying goodbye to Dropbox and hello to SpiderOak Hive
81–90 of 120 posts
Re: Why I'm saying goodbye to Dropbox and hello to SpiderOak Hive
#82Chicago? Last time I checked, that city is within the jurisdiction of the United States and not immune to national security gag letters. No thanks. Swiss based Wuala.com is a much better solution.
Re: Why I'm saying goodbye to Dropbox and hello to SpiderOak Hive
#83Chicago? Last time I checked, that city is within the jurisdiction of the United States and not immune to national security gag letters. No thanks. Swiss based Wuala.com is a much better solution.
I use Wuala, but only because I think I can trust more Swiss than US based software company. That being said, it's all about trust, since both are closed source and there's only trust that's left to the users. I wish there existed an ubiquitous open source alternative.
The big advantage of Tarsnap is that it supports efficient encrypted deduplicated snapshots; it only stores block that have not been stored before, so you can have many versioned backups using much less space than they would otherwise.
Re: Why I'm saying goodbye to Dropbox and hello to SpiderOak Hive
#84Earlier quoted context omitted.
Hey I'm no expert, and have absolutely no evidence , but do know that there was an issue some years ago where the Swiss were allegedly strong-armed by the IRS into lifting their privacy restrictions [1] and [2]. The story, as I remember it, was that Swiss banks had to share information about US depositors with the IRS if the Swiss wanted to continue operating offices is the US. While I trust the Swiss a lot more than…
You're correct - but only with the big international banks. The tax issue is a different can of worms. At least there's a pretty good chance that NSA doesn't have a back door to wuala.
Re: Why I'm saying goodbye to Dropbox and hello to SpiderOak Hive
#85Oh, you're saying it wouldn't be possible with client-side encryption? I say it should be, using a mix of symmetric and asymmetric encryption:
- have all data of a repository encrypted using a symmetric key, at first known only by the repository owner.
- the symmetric key gets sent on the cloud host's server, encrypted using the owner's public key.
- every new device or share with a new user will require a previous user (in this case the owner) to decrypt the symmetric key using his private key and encrypt it using a new public key that the new user / device has sent together with its access request.
- the cloud host simply grows a table of encrypted symmetric keys, with one entry per device/user, besides the actual encrypted data. note that the cloud host still can never decrypt the data, as long as the private keys never get sent around.
Re: Why I'm saying goodbye to Dropbox and hello to SpiderOak Hive
#86We tried SpiderOak but the security was hard for our users. We ended up using Syncdocs which encrypts Google Drive. It lets our team share and use Google Docs normally, but secure folders we need to keep encrypted. They also disclose their AES encryption source.
http://www.syncdocs.com/forums/topic/syncdocs-encryption-is-...
Re: Why I'm saying goodbye to Dropbox and hello to SpiderOak Hive
#87What's disappointing about SpiderOak is the inability to do two-way sharing of your data - so it's not really usable in a corporate setting. Oh, you're saying it wouldn't be possible with client-side encryption? I say it should be, using a mix of symmetric and asymmetric encryption: - have all data of a repository encrypted using a symmetric key, at first known only by the repository owner. - the symmetric key gets s…
In any case, it's on the way, and it's entirely open, built with Crypton.io, our new open source framework for building zero knowledge applications. (Which we'll eventually port the main SpiderOak desktop app to use.) For details https://crypton.io/ and https://www.youtube.com/watch?v=pn9DAwggza0 (...and to be clear, the threat model is intended for for HTML5 desktop and mobile apps, not browser Javascript.)
Re: Why I'm saying goodbye to Dropbox and hello to SpiderOak Hive
#88I'm embarking on my own backup solution: For $1.38 USD/month (Ramnode OpenVZ SSD-Cached 128mb RAM VPS with 31% off for life coupon) I get 50gb. I just need to setup a synchronization/encryption schedule. I'm thinking rsync remotely to the server. Not sure on encryption yet. I'm also using the servers as development and minor hosting for myself. It's practically a free storage solution? Am I crazy?
Re: Why I'm saying goodbye to Dropbox and hello to SpiderOak Hive
#89Re: Why I'm saying goodbye to Dropbox and hello to SpiderOak Hive
#90Earlier quoted context omitted.
Isn't switching from one closed source backup system to another closed source system overlooking the elephant in the room? These companies are legally required to rat you out when the government comes knocking (some even doing so without demanding a valid warrant, and profiting from LEO requests). SpiderOak has been saying they "expect to make the SpiderOak client code open source in the not-distant future" [1] for y…
I recently created a "petition" for SpiderOak to open source the client (and allow people to build it themselves from source) so that people can let SpiderOak know their thoughts. The petition signatures are sent to SpiderOak. It's still available at the link below if any SpiderOak user (or potential customer) wants to use it to "show the numbers" on a single site (as opposed to scattered comments): http://www.change…