Megabad: A quick look at the state of Mega’s encryption
arstechnica.com
Megabad: A quick look at the state of Mega’s encryption
1–10 of 60 posts
Re: Megabad: A quick look at the state of Mega’s encryption
#2Re: Megabad: A quick look at the state of Mega’s encryption
#3How could they de-dupe stuff without knowing what it is in the first place?
Re: Megabad: A quick look at the state of Mega’s encryption
#4Symmetric encryption means the same key is used to encrypt and decrypt your data; this is less secure than asymmetric encryption (where one key encrypts and a different key decrypts), but it's faster and easier to implement.
Isn't that comparing apples to oranges? What would be the benefit for Mega or the user to switch to RSA for that? Encryption would be using a symmetric cipher anyway, unless I'm missing something.
Re: Megabad: A quick look at the state of Mega’s encryption
#5I'm most curious to find out more about the de-duplication issue. Could this be a carry-over from their previous ToS where someone just didn't put 2 and 2 together? How could they de-dupe stuff without knowing what it is in the first place?
Re: Megabad: A quick look at the state of Mega’s encryption
#6I don't understand that part: Symmetric encryption means the same key is used to encrypt and decrypt your data; this is less secure than asymmetric encryption (where one key encrypts and a different key decrypts), but it's faster and easier to implement. Isn't that comparing apples to oranges? What would be the benefit for Mega or the user to switch to RSA for that? Encryption would be using a symmetric cipher anyway…
Re: Megabad: A quick look at the state of Mega’s encryption
#7I don't understand that part: Symmetric encryption means the same key is used to encrypt and decrypt your data; this is less secure than asymmetric encryption (where one key encrypts and a different key decrypts), but it's faster and easier to implement. Isn't that comparing apples to oranges? What would be the benefit for Mega or the user to switch to RSA for that? Encryption would be using a symmetric cipher anyway…
Re: Megabad: A quick look at the state of Mega’s encryption
#8I don't understand that part: Symmetric encryption means the same key is used to encrypt and decrypt your data; this is less secure than asymmetric encryption (where one key encrypts and a different key decrypts), but it's faster and easier to implement. Isn't that comparing apples to oranges? What would be the benefit for Mega or the user to switch to RSA for that? Encryption would be using a symmetric cipher anyway…
You're not missing anything. I clenched my teeth when I red this phrase. It doesn't mean anything and discredits the whole article as it shows the author has got a superficial knowledge in cryptography.
Re: Megabad: A quick look at the state of Mega’s encryption
#9A rather good write-up, though I'm not convinced the author's points justify the "Megabad" in the title. The decisions made are not always the most secure, but in general appear to be reasonable given the nature of the service - i.e. that this is material meant to be shared not just backed up.
Re: Megabad: A quick look at the state of Mega’s encryption
#10It is in there interest to do de-duplication and as they are still required to remove files under the DMCA it will just mean that multiple people loose there infringing files at once. All someone then needs to do to upload the file again is change one byte.
The encryption also stops them from being able to implement a back door for the content industry to police the site themselves as was the case with megaupload.