Megaupload Is Dead. Long Live Mega
wired.com
wired.com
So now that they have this new approach I doubt they'll be successful. Because of the way the new Mega is set up you can't search for content. Allowing the ability to search for content would necessitate getting rid of their whole privacy scheme. I predict that the new Mega could still be used to share copyrighted files but the onus will be on third parties to keep track of such files in a database or something in order to provide links to people searching or it can just become a safe place to store your copyrighted files and share them on a case by case basis (through email, links on forums, or wherever). But if this really is supposed to be a legit service, which it isn't (come on, you know it), then I don't see how it can gain market share or mind share given the alternatives we already have had for a while now.
Could you search on the old MegaUpload? For MegaVideo at least, I seem to remember that third party sites were all but required to find what you want.
I wasn't really aware of megaupload until the bust happened. Maybe I don't spend enough time looking for pirated copies of Lady Gaga albums.
So that's a third option for you.
You're attributing to arrogance that which can be adequately explained as a desire for plausible deniability. If Mega acts like a legitimate file depository site, and they don't do noticeably more to help with copyright infringement than things like Google Drive, and they say that they're legit, then this decreases their chances of getting in more legal trouble.
In one of the articles discussing his arrest it was mentioned that they had an internal tool that could search for content, maybe that is what you're thinking about.
BTW. in Poland there's a well-known sharing service that operates this way; promptly deleting infringing content, while everybody knows that the files will reappear shortly somewhere else, and it's all Google-indexed (I don't think that it's by coincidence), so with simple "site:" query you can even skip the paid search feature.
And more to the point, they could put the onus on Mega to go do that. It would be easy to argue in court "if we can find the key, so can they, if we can check the file, so can they" and cast their actions as wilful negligence.
It's not so much whack-a-mole, as "keep it quiet", then. Mega pretty much has to kill what they can find the keys to, but if you keep the key a secret and share it sparingly, that is no longer possible.
Reasons I can think of using "Mega" instead of another service include (1) DL speed, (2) brand recognition, (3) less intrusive ads and less annoying capchas due to their superior financial position and scale stemming from their name recognition.
I wonder if the reasons above (or others) will be strong enough to transition Megaupload users to "Mega"
That way you can link encrypted content with a key, and have the server not know about it.
This scheme has been deployed for at least one secure pastebin.
"...easily on MegaUpload because that's basically what everyone was using it for"
You can never blame the creators of a tool for what their users do. Not to rehash an old argument, but you don't blame suitcase manufacturers for making suitcases that criminals use for convenient cash lockboxes. You can't blame a knife maker because a housewife stabbed her husband.
Unless you can empirically prove that MegaUpload courted people to break copyright I don't see what case you have. All of your "claims" seem to be anecdotal bluster, couched in a defensive posture to automatically discredit anyone who disagrees.
I find it so hard to comprehend that people refuse to believe that MegaUpload was never used for legitimate reasons. It's widely known that MegaUpload was well used in the corporate world[1], however it's unfortunate that no specific companies (to my knowledge) have come forward publicly. As a personal aside, I used it many times to send files that were too large for email to classmates and friends.
Beyond all of that, you are overlooking the problem. Attacking filesharing websites is simply slapping a band-aid over a symptom. The websites will continue to pop up, there is a demand and someone is going to supply it. Plus, it's incredibly easy to set up your own file-sharing website... I expect it won't be too soon before we start seeing people rolling their own just like blogs today (though admittedly not nearly as widespread).
We need to be addressing the real issue. Admittedly, I don't have a solution to "piracy" on a grand scale, however I can certainly say actions like targeting MegaUpload and then vilifying a business that has yet to even land a single customer over it's first press release definitely do not help the issue.
[1] http://arstechnica.com/business/2012/01/before-shutdown-mega...
Edit: phrasing
Since the recorder wasn't explicitly made for breaking the law, the makes of the recorder can't be held accountable.
[1] http://en.wikipedia.org/wiki/Sony_Corp._of_America_v._Univer....
Here's a discussion on rpgmaker developers site about megaupload going down: http://www.rpgmakervx.net/index.php?s=e2dfd62fff9638c7224860...
And there's hundreds of sites like that, people creating content on different platforms that need a way to share it. How do you think they share their creations?
It's very presumptuous to assume you know the reason why the Feds raided MU.
If the Feds had a case they should have presented it. Not all this "we have evidence, but we won't show it to anyone" crap.
With the fact that they had been spying on MU for over 5 years, you would think they could have built a solid case, and the fact that they couldn't makes one think the raid was rushed.
Perhaps this had more to do with the Universal lawsuit, the pending release of MegaBox, and pressure from lobbyists than actual wrongdoing.
Of course this is all conjecture, as is your assumption.
The question remains however, how big a part of "what was going on at MegaUpload" involved copyright infringing data. The article implies that the old MegaUpload was indeed using data deduplication. The Feds confiscated 25 petabytes of data. It just doesn't add up if you consider all Blu-Ray releases in the movie industry to date (which at 10GB a piece would make up the vast majority of infringing data). The only conclusion (that makes any sense to me) is that the vast majority of those confiscated 25 petabytes (about 95% if I remember my previous back-of-the-envelope calculations correctly) must have been legit user-generated or individually produced data, such as the 4GB photos that are mentioned elsewhere in this thread, or who knows what it could be, raw video data, the only reliable way to share huge amounts of sensor readings from whatever instruments for scientific research maybe. I have no idea, but given they used deduplication, Hollywood just didn't produce that many films. 25 petabytes are huge.
Don't get me wrong, it still means they were infringing on an enormous scale, just that it wasn't quite entirely fair to just take and hold the whole 25 petabytes, they don't do that when Google infringes either.
But my inner policeman hesitates. If actual bad guys (organized crime, drug cartels, spies, terrorists, governments, script kiddies, or anyone else working outside the law) can communicate and operate with impunity, the technology is not an unequivocally good thing. The broadly accepted way we deal with this is to have warrant-based interception and eavesdropping; it's hard to argue that our law enforcement services would best operate without any tools other than direct physical surveillance. So presumably even Mega would need to comply with legal wiretapping requests. Happily for Mega, and unhappily for law enforcement, doing it at the server doesn't get them anything with this scheme. But that simply compels law enforcement to get much more invasive, in a way that's hard for citizens to monitor: Find a way to install eavesdropping tools on the suspect's machine so access is gained before encryption.
I'm not sure where all this is headed; it's a brave new world.
(Heading off potential replies about the growing use of warrantless wiretaps -- of course those are unacceptable. But wiretapping with a warrant is a vital, crucial tool, and that's all I'm discussing here.)
This tool is still just a cyber-locker, it doesn't allow you to launch a ddos attack, or run scripts, or even communicate, you need a channel of communication established elsewhere to pass the keys. It's just an easier way to share files with people you're already communicating with in some manner.
http://en.wikipedia.org/wiki/In_re_Aimster_Copyright_Litigat...
The court held that in this case the users of the systems were the direct infringers, these who are ignorant or more commonly disdainful of copyright and in any event discount the likelihood of being sued or prosecuted for copyright infringement, however companies such as Aimster that facilitate their infringement, even if they are not themselves direct infringers can be liable for copyright violations as contributory infringers.
The key question is whether Mega is practicing "Willful Blindness" (http://en.wikipedia.org/wiki/Willful_blindness) by providing this service. The players involved, especially Dotcom, seem to have already "tainted" themselves as being _knowledgeable_ of infringement through their involvement in MegaUpload. So in what way is their "design" of a client-side encrypted system different from "designing" a drug trafficking briefcase so that the courier doesn't have a key? If the courier/service has reason to believe that the service is being used for copyright infringement, it could be argued that they are being criminally negligent by offering such a service.
All they are doing is keeping private communication really private.
What is the difference between this and encrypted email? Hint, you can break a large file into many chunks of email too.
(No really, I'd rather hear more about what happened to the poor Demonoid guys than see his face taking up more media space - it's obvious that he likes publicity even more than money so even the FBI just gave him what he wanted!)
Why would a person host their entire company from one location, like AWS US-East?
How? Is this if the person that uploaded the file is openly distributing the key?
It's fairly routine for large media sites to supply this access, since it's more about administrative efficiency for the hosting site than anything else.
This is just as it worked before.
The only difference really is that they can't apply deduplication to uploaded content.
Of course, all of this assumes that they get the crypto right in the first place.
How is that pattern any different from a musician legitimately distributing an mp3?
And what if someone uploads a wikileaks like pdf that gets downloaded by thousands of people? Is that going to get automatically shut off.
Javascript has no way to output data that is then saved to disk.
It will have to be a browser extension or an offline tool (download the encrypted file, decrypt it once you are done).
However I shudder to think about how much malware people are going to get from sites purporting to make "special megaupload decryption tools".
First, there's HTML5 window.saveAs which apparently nobody has implemented. Second, you can always fall back to some swf.
http://stackoverflow.com/questions/2897619/using-html5-javas...
FileSaver.js implements the W3C saveAs() FileSaver interface in browsers that do not natively support it.
No IE support, but what’s the intersection of Mega users and IE users?
Part of the point of this is to make the problem too big to raid, too many people to litigate.