The example in the article shows the decryption key as a URL fragment, which never hits the wire. A subpoena on Mega's own servers is one thing, but a court compelling them to collect keys from client machines? I would hope not.
http://www.wired.com/2007/11/hushmail-to-war/
People pretty much have no option but to comply with court orders. Most people are not going to go to jail so that other people can continue distributing stuff.
This should be a worry with Mega and its current owners.
Notice the format of the URL
example.com/fileA#encryption-key
All MEGA has logged is: example.com/fileA
encryption-key
is generated client side and only sent to recipients, not the provider.
The fragment is only ever transmitted by the uploaded to the recipient. I'm not familiar with Mega but presumably this transmission is also encrypted.
So your chance of getting it is low.
And certainly Mega can deny ever receiving it.
The point wasn't that mega can deny ever getting the key - the point was that this "security" system in place is very obviously designed to workaround the problem of mega knowing what files they were trading. This would probably be viewed as willful blindness and not actually protect them in court:
This link[0] explained it reasonably well to me, though I'm still not sure on the security implications of pinning JS through it.
[0] https://github.com/slightlyoff/ServiceWorker/blob/master/exp...
> A famous example of such a defense being denied occurred in In re Aimster Copyright Litigation, 334 F.3d 643 (7th Cir. 2003), in which the defendants argued that the file-swapping technology was designed in such a way that they had no way of monitoring the content of swapped files. They suggested that their inability to monitor the activities of users meant that they could not be contributing to copyright infringement by the users. The court held that this was willful blindness on the defendant's part and would not constitute a defense to a claim of contributory infringement.