If they had the files unencrypted, the rights holder could demand that every copy of file `foo` be removed. With this design, multiple uploads of the same file are not identifiably the same by MEGA, so that case can't happen.
It's interesting that they decided the benefit of encryption (lessened responsibility, marketing) outweighed the cost of wasted storage space for dedupe-able content.
They got caught, big time, last time over the fact that they were doing de-duplication on upload of content, and then when they received a DMCA for only one of the URLs, only taking /that/ one down -- even though they know it's actually also available in a bunch of other places.
The example in the article shows the decryption key as a URL fragment, which never hits the wire. A subpoena on Mega's own servers is one thing, but a court compelling them to collect keys from client machines? I would hope not.
http://www.wired.com/2007/11/hushmail-to-war/
People pretty much have no option but to comply with court orders. Most people are not going to go to jail so that other people can continue distributing stuff.
This should be a worry with Mega and its current owners.
Notice the format of the URL
example.com/fileA#encryption-key
All MEGA has logged is: example.com/fileA
encryption-key
is generated client side and only sent to recipients, not the provider.
The fragment is only ever transmitted by the uploaded to the recipient. I'm not familiar with Mega but presumably this transmission is also encrypted.
So your chance of getting it is low.
And certainly Mega can deny ever receiving it.
The point wasn't that mega can deny ever getting the key - the point was that this "security" system in place is very obviously designed to workaround the problem of mega knowing what files they were trading. This would probably be viewed as willful blindness and not actually protect them in court:
This link[0] explained it reasonably well to me, though I'm still not sure on the security implications of pinning JS through it.
[0] https://github.com/slightlyoff/ServiceWorker/blob/master/exp...
> A famous example of such a defense being denied occurred in In re Aimster Copyright Litigation, 334 F.3d 643 (7th Cir. 2003), in which the defendants argued that the file-swapping technology was designed in such a way that they had no way of monitoring the content of swapped files. They suggested that their inability to monitor the activities of users meant that they could not be contributing to copyright infringement by the users. The court held that this was willful blindness on the defendant's part and would not constitute a defense to a claim of contributory infringement.