Data is encrypted with your password on the client side, your password never leaves your PC. They published a paper on their security implemenation: http://ieeexplore.ieee.org/xpl/freeabs_all.jsp?arnumber=4032...
It allows to synchronize multiple folders and it gives access to a certain number of previous versions. You can also share folders with friends, publicly or via a secret link.
It's cross-platform: Win, Mac, Linux.
I'm a happy customer since more than a year (it's free up to 2GB though) and I wonder why so few people know about it.
If you want to send something to someone, that means you need to securely communicate the key to them first or take the SpiderOak approach of "We guarantee security locally but if you share a file = file is shared unencrypted".
Provided that no man in the middle attacks take place during the "friendship" operation :)
There is a slight benefit to "must ship trojaned software to recover passphase, then decrypt" vs. "just access data server-side", but in practice, if your threat is the government, there's not a huge difference. If your threat is a server break-in by a third party, then there's some difference.
Overall, probably the best bet, if you don't run your own servers, is Dropbox plus your choice of well tested encryption on top. As for your best well-tested encryption, that's a hard problem too -- Truecrypt has a pretty wide following and some versions have been audited, and source is published. For general purpose use on Macs, I just use Apple's encryption -- it's probably ok, but as far as I know, hasn't really been analyzed by third parties (I'd be happy to NDA and look at it). I rationalize it as if Apple is subverted, and I use OSX, I'm fucked even if third party disk encryption software itself is safe.
The short story is that Dropbox + Truecrypt work fine, but may not (or may!) be optimal.
Here is a nice overview of its use on OS X: http://www.packetslave.com/2011/04/21/dropbox-encryption-w-e...
Moreover they don't even store your password in the server (sign in is locally handled), and they claim to have a zero-knowledge policy. As other said, you have to ultimately trust them; however the want to release under an open source license their client software, so one should be able, eventually, to check their claims.
[^1]: https://spideroak.com/download/referral/b26d996944aeed4254f6... (careful, it's a referral)
Edit: removed the link inline.
All files get encrypted and are stored redundantly. No one unauthorized - not even Wuala as the provider - can access the files.
If someone wants to encrypt their data, then they'd probably want to know the physical security around the box holding their data too. Stallman's probably mentioned this at some point.
- Wuala runs on dedicated machines in (i think three) different data centers. It isn't their own data center though.
- Data is encrypted on the client side.
- Wuala is hosted outside of the US or US jurisdiction
They say in their FAQ that their servers are in secure server farm in Switzerland, Germany and France.
Runs on Win, Mac, Linux, iOS, Android.
* It seems to be closed source
* The German government is involved (Close friends with the US)
The German gov is involved?! Ha ha, the North Koreans as well?
Dropbox kicks ass as "file system of the internet" but sharing files with people in a secure and private way with dropbox is a big pain.
With next release we will integrate with dropbox and Google Docs as well.
Disclaimer: I am from TitanFile
Hybrid Storage with multiple access methods : Web, Desktop (Win/Mac), Mobile & FTP.
Flexible subfolder sync with versioning