Dropbox acquires Boxcryptor assets to bring zero-knowledge encryption to storage
techcrunch.com
techcrunch.com
I kept reading, trying to find the innovative way of encrypting large amount of data while not revealing the same key to all participant - some SSS variant or fast FHE or maybe a cool new PRE.
Also, all value added features besides shipping the bytes are gone when something like this is in effect. Search, preview, co-edit, metadata extraction.
I guess I’m disappointed / venting because of crushed hopes. I’m in this field and hoped something new and exciting is starting. Not trying to criticize the engineering work, which looks quite well done, just sad there isn’t new algorithmic development.
FHE: Fully Homomorphic Encryption
All of these are true “zero knowledge” methods that don’t require the encryption key to be shared, and therefore be granted irrevocably.
But I guess you can do the same with rclone given that it supports encryption, mounting and the local filesystem.
I am not sure however how they compare in simultaneous read/write access by multiple users.
Unfortunately Cryptomator isn’t as reliable as Boxcryptor.
I have not had this experience. I switched to Cryptomator because it was a much smoother and more reliable experience for my use cases. What issues did you have?
Cryptomator has been good to me otherwise!
https://techcrunch.com/2022/11/29/dropbox-acquires-boxcrypto...
Dropbox announcement:
https://blog.dropbox.com/topics/company/dropbox-to-acquire-b...
Looks like Dropbox plans to provide client side encryption, although somewhat belatedly.
to business users
Generally we prefer the best third-party article (if there is one) to a corporate press release: https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu....
This way you can have deduplication of data, and only an attacker that knows the content of the file can decrypt the file, but since they already have the file, it does not matter.
1. You can tell that the user posses a known file. Such as a pirated movie. This is what this thread is about.
2. If the attacker knows the file except a sufficiently small secret part, they can learn that part.
https://tahoe-lafs.readthedocs.io/en/latest/convergence-secr...
These products need to be available for end consumers too though not just b2B
All my essential, must have info is stored on two 128GB microSD cards. One lives in a safe at home. The other I strap to my wrist. The cards are encrypted with BitLocker. A few trusted others have the decrypt/safe key.
The data is as safe as I am --- if not safer. If something does go bump in the night, all I have to worry about is my own personal safety. Even if I die unexpectedly in an accident, search and rescue will still likely deliver the data to my next of kin.
Let's face it --- no one is going to organize a search party if your on-line backup suddenly disappears or is being held hostage for "egress fees".
Photos, last will and testament, legal documents, bank/accounting/tax info, photocopies of birth certificate/passport/diplomas, source code, login/access credentials, crypto keys, etc., etc.. All the same stuff that people like to use on-line backup for.
And none of these make sense to have on your wrist 24/7.
I run my own company. I have 20 years of source code and legal documents that are essential to my company --- among other things. Lots of time, effort and money is tied up in this info and it is not easily replaced.
And none of these make sense to have on your wrist 24/7.
You're entitled to your opinion of course but it might carry more weight if you would explain/justify instead of merely state.
Less than ten years after I graduated high school, the district had already migrated SIS platforms and had lost my freshman year transcripts. I have the only copy.
I’m in the same position as you with respect to having business records that I’m the custodian of, which aren’t readily or realistically restorable if I don’t make my own backup arrangements.
For anything truly important, you can’t assume someone else has your disaster recovery interests in mind.
I know exactly where my data is at all times. And I know it is at least as safe as I am. Actually, it is safer since I keep 2 copies --- one stays at a fixed location and one travels with me at all times.
I spent some time contemplating the possibilities and this is a simple, easy plan that will likely survive even my death.
I always update the one on my wrist as needed first. If there are lots of changes, I use XCOPY to scan/copy updated files only from the wrist card to the one kept in a safe. Otherwise, I may make the same updates to both manually.
I keep two separate copies --- in case of failure.
Get one of these tiny cases printed, glue it to the inside of a NATO watch strap, or you can forgo the case and see how it holds up.
The card slides into a slot in the side and latches into place. SD cards are designed with a latch key just for this purpose.
I keep 3 (!!) RFID tags on my wrist using my Pebble 2SE and a NATO strap, they're 100% unnoticeable and invisible aside from added functionality.
I'd love to add storage for microsd to it; especially if it doesn't impact my current method