Live data from Hacker News

Kim Dotcom's New Mega Encrypted Cloud Storage

forbes.com

41–50 of 98 posts

Re: Kim Dotcom's New Mega Encrypted Cloud Storage

#41

Earlier quoted context omitted.

But Dropbox is a YC company. Why do you need the assurance of some fancy acronym like AES?

Is a fancy acronym like YC any better? I would trust the founders not to look at private data, but any company that has employees is vulnerable to one of them going rogue.

Exactly. In addition: If on court order someone wants to access my data in the cloud, even (or especially) a YC company will follow the order.

The only protection against that is that the cloud storage provider doesn't have the encryption keys.

Re: Kim Dotcom's New Mega Encrypted Cloud Storage

#42
post #39
post #31

MEGA could be the only cloud storage I'd actually start trusting. I don't use Dropbox, I don't use Google Drive or anything else, because I'm not interested in other people being able to peep at my data. While I don't perceive Dotcom as a trustable character, his incentive to NOT store any encryption keys on the servers is much higher than any of his competitors.

You're not tempted by Tarsnap? Wuala claim to be unable to access your files ( https://www.wuala.com/en/learn/technology ) (but who knows if they're lying?)

According to the site "Wuala protects your privacy: In stark contrast to most other cloud storage services, all your files get encrypted on your computer, so that no one - including the employees at Wuala and LaCie - can access your private files. Your password never leaves your computer."

Re: Kim Dotcom's New Mega Encrypted Cloud Storage

#44
post #36

So this says all files will be encrypted with RSA, doesn't that mean who ever wants to access them needs the key? Is this just not a successor to Megaupload then? How will sharing files publicly work? Or will it at all?

You could do that if there is a per-file key. But you'd need some client software to store and manage keys for individual files for easy exporting urls including these keys, and I read that MEGA is managed only via web (at least now).

Re: Kim Dotcom's New Mega Encrypted Cloud Storage

#45
post #37

http://www.spideroak.com has been doing this for years. Nothing new to see here.

There's a bunch. Some are better than others. Here's a list, taken from ( http://www.kimpl.com/1297/secure-online-backup-file-sync-ser... ) which also has some reviews. ( https://www.sugarsync.com/ ) ( https://www.dropbox.com/ ) ( https://www.wuala.com/ ) ( https://www.syncplicity.com/ ) ( https://mozy.com/ ) As others say, there's a difference between syncing and hosting; between levels of security; between ease of…

There aren't a bunch. Sugarsync and Dropbox only offer encrypted transport of your files. To actually encrypt the files/folders themselves requires a 3rd party piece.

Mega offers everything wrapped in encryption, so presumably, his company will have plausible deniability (zero knowledge) of the files/folders that his service is being used for.

From a technical standpoint, I also believe it makes de-duplication impossible but someone with more knowledge on that subject can comment on it.

Re: Kim Dotcom's New Mega Encrypted Cloud Storage

#46
post #31

MEGA could be the only cloud storage I'd actually start trusting. I don't use Dropbox, I don't use Google Drive or anything else, because I'm not interested in other people being able to peep at my data. While I don't perceive Dotcom as a trustable character, his incentive to NOT store any encryption keys on the servers is much higher than any of his competitors.

But Dropbox is a YC company. Why do you need the assurance of some fancy acronym like AES?

YC doesn't control Dropbox. Whatever trust you have in a minor shareholder, it shouldn't translate to trust for the company.

There are other reasons as well: potential vulnerabilities in their software, malicious/crazy/corrupted employees, etc. Healthy need-to-know rule is enough to decide that if there's no reason your cloud provider should have access to your data, he shouldn't have it.

Re: Kim Dotcom's New Mega Encrypted Cloud Storage

#47
post #31

MEGA could be the only cloud storage I'd actually start trusting. I don't use Dropbox, I don't use Google Drive or anything else, because I'm not interested in other people being able to peep at my data. While I don't perceive Dotcom as a trustable character, his incentive to NOT store any encryption keys on the servers is much higher than any of his competitors.

As long as a limit of 2GB is okay for you, you can have both the privacy and the "trustability": https://spideroak.com/faq/category/privacy__passwords/

Re: Kim Dotcom's New Mega Encrypted Cloud Storage

#49
post #31

MEGA could be the only cloud storage I'd actually start trusting. I don't use Dropbox, I don't use Google Drive or anything else, because I'm not interested in other people being able to peep at my data. While I don't perceive Dotcom as a trustable character, his incentive to NOT store any encryption keys on the servers is much higher than any of his competitors.

Use SpiderOak[0] then. They assure strong zero-knowledge privacy and, while the client isn't technically open source, much of it is completely unobfuscated python. I definitely trust SpiderOak with my data. It also has more features than Dropbox or Drive... You can set syncs as between a subset of all devices, create an arbitrary number of syncs, and create some backups which aren't syncs too. It's quite nice.

Another service which is open source is Tarsnap[1]. It doesn't do syncing or have a free tier, but it's definitely trustable online storage.

In both of these cases the encryption keys are not on the servers.

An additional provider which claims to offer cloud storage/backup with zero-knowledge is Crashplan[3]. I wouldn't trust them as much as either of the previous options, but I still think they're telling the truth. I note it partly because I really like their approach. You can a) let them keep the key and thus you can still reset your password etc, b) let them keep the key so you don't have to transfer it manually to all crashplan-using computers, but have it encrypted on their end with a password only you know (can't be reset), or c) provide your own key which they claim they'll never know. These three tiers make sense and at each one you sacrifice some usability (such as the web-interface being unusable at (c) I think) in exchange for security.

So yeah, dropbox and google drive are both obviously able to look at your data, but that doesn't preclude using other cloud storage providers. There's many that are trustworthy and have the code to prove it. In the case of Mega, I'd trust them less than the typical one. They're big enough that the government will notice them... they'll need to make it usable (allow password resets etc), it looks like you upload unencrypted data and then they encrypt it server-side (edit: turns out it's client side javascript encryption. Downside there is it'll probably be a bit slow)... All of these are problems. If it's not sent already encrypted with a key they've never touched then the government could court-order them to alter the software to store unencrypted copies or to keep encryption keys. Since they're the one giving you the key they obviously know it at some point, however briefly, and they are thus vulnerable. Forcing users to generate and supply keys just isn't user-friendly on a web-only application. The only way you can make that work, as SpiderOak did, is have the user download an application which seamlessly does all the crypto work.

[0]: https://spideroak.com/ [1]: https://www.tarsnap.com/ [2]: http://support.crashplan.com/doku.php/articles/encryption_ke...

Re: Kim Dotcom's New Mega Encrypted Cloud Storage

#50
post #39

Earlier quoted context omitted.

You're not tempted by Tarsnap? Wuala claim to be unable to access your files ( https://www.wuala.com/en/learn/technology ) (but who knows if they're lying?)

According to the site "Wuala protects your privacy: In stark contrast to most other cloud storage services, all your files get encrypted on your computer, so that no one - including the employees at Wuala and LaCie - can access your private files. Your password never leaves your computer."

I think Hushmail made the same claims, until compelled by law enforcement to send altered client software to the machines of suspects.

Not sure how these other companies operate, but unless the user hand-encrypts files with openssl, gpg, pgp, etc., then the trusted client software has the potential to be a vector for compromise.

Post reply on HN