Kim Dotcom's New Mega Encrypted Cloud Storage
forbes.com
forbes.com
What's different between Megaupload and Dropbox or any of the others? If the Feds (and the Motion Picture industry) decide that Dropbox is hosting pirated works they could suffer the same fate, no?
I am not focusing on Dropbox here. They are just a place holder for any storage/sharing service you'd care to name. I use Dropbox almost exclusively and love it.
The point here is that, unless I am wrong, your data isn't safe anywhere outside your own four walls. So, if data loss is your concern, be sure to back it up locally.
If you do things right it should not matter if Mega (or any other service) implodes overnight. Set yourself up to not loose anything if that were to happen. If you do that, then you can use any service and sleep well knowing that such a failure (or confiscation by the Feds) is of minimal or no consequence to you.
I'd say at its present state, MEGA servers are one of the least likely to be raided, considering the clusterfuck with the last raid.
> if data loss is your concern, be sure to back it up locally
That's a horrible advice. A company that does data storage professionally is much less likely to lose your data. If you have a house fire or a major flood, your computer and your backups will be gone.
Diversification is the key to data safety. Back up both locally and online.
In my case it means that I keep three full backups of everything at three different locations and with various incremental and full-backup schedules. Old data that doesn't see a lot of activity is archived and even burned to DVD and stored in a fire-proof safe. I know that some of it is a bit extreme, but I actually take my work product very seriously and most of it represents "cubic hours" of work. I take the position that my business data is my responsibility and I store it "locally" with enough redundancy that it would take a pretty major event for a significant chunk to be lost.
That does NOT mean that I don't use remote storage/backup services. It DOES mean that I operate as if they could be reduced to dust tomorrow. Which, in turn, means that I have all of the convenience some of these services offer while not having to worry too much about issues at the backup provider ruining my life.
I think it's you who doesn't understand the meaning of "locally".
And if they get raided, the Feds won't have shit against Mega or you.
About the backup part, they have servers in different countries, so it's safer. Personally, I wouldn't rely on any service alone, I always have an extra copy somewhere else. I do the same with my emails for example. If tomorrow my email provider shuts me down, I will lose at most ~12 hours of emails. All my other emails are in my PC and in Dropbox (encrypted, obviously). Next, I sign up to a different email provider, change my domain DNS, and keep receiving emails normally like if nothing happened.
I think the most accurate thing you could say is that the odds vary considerably based on the intentions and actions of the operators with respect to criminal activity, and the extent to which they can be inferred by reputation.
Framed as practical advice, I'd say: Your data is probably much safer with services that don't have a reputation for being used mostly for piracy.
With Dropbox, I only have to worry about maintaining one place, the Dropbox. It syncs across all my devices.
Without that, I'd have to sync files manually whenever I delete/rename/change them... I hope you see that it's not the same.
It's not file storage that presents the political risk - it's letting idiot kids store things publicly, for free, because you are pursuing some "make it up on volume" business model that we all knew was broken 13 years ago.
/rant
Reading their TOS makes me not want to use the service (but thats true to any other "cloud storage" provider aswell).
While I don't perceive Dotcom as a trustable character, his incentive to NOT store any encryption keys on the servers is much higher than any of his competitors.
The only protection against that is that the cloud storage provider doesn't have the encryption keys.
There are other reasons as well: potential vulnerabilities in their software, malicious/crazy/corrupted employees, etc. Healthy need-to-know rule is enough to decide that if there's no reason your cloud provider should have access to your data, he shouldn't have it.
Dropbox being a YC company means absolutely zero other than that YC liked their idea and supported them. That doesn't give me any assurance that they won't make a mistake or that an employee won't sell my data.
In fact, Dropbox, despite being a YC company, already slipped up majorly once to the point that every account was completely passwordless. You could just type in random emails at the web login and view some stranger's files. Story here: http://techcrunch.com/2011/06/20/dropbox-security-bug-made-p...
On the other hand, AES has yet to slip up. My AES encrypted data will take a significant fraction of the life of the universe to crack and, YC or no, a single programmer error won't break it.
Wuala claim to be unable to access your files (https://www.wuala.com/en/learn/technology) (but who knows if they're lying?)
Not sure how these other companies operate, but unless the user hand-encrypts files with openssl, gpg, pgp, etc., then the trusted client software has the potential to be a vector for compromise.
Another service which is open source is Tarsnap[1]. It doesn't do syncing or have a free tier, but it's definitely trustable online storage.
In both of these cases the encryption keys are not on the servers.
An additional provider which claims to offer cloud storage/backup with zero-knowledge is Crashplan[3]. I wouldn't trust them as much as either of the previous options, but I still think they're telling the truth. I note it partly because I really like their approach. You can a) let them keep the key and thus you can still reset your password etc, b) let them keep the key so you don't have to transfer it manually to all crashplan-using computers, but have it encrypted on their end with a password only you know (can't be reset), or c) provide your own key which they claim they'll never know. These three tiers make sense and at each one you sacrifice some usability (such as the web-interface being unusable at (c) I think) in exchange for security.
So yeah, dropbox and google drive are both obviously able to look at your data, but that doesn't preclude using other cloud storage providers. There's many that are trustworthy and have the code to prove it. In the case of Mega, I'd trust them less than the typical one. They're big enough that the government will notice them... they'll need to make it usable (allow password resets etc), it looks like you upload unencrypted data and then they encrypt it server-side (edit: turns out it's client side javascript encryption. Downside there is it'll probably be a bit slow)... All of these are problems. If it's not sent already encrypted with a key they've never touched then the government could court-order them to alter the software to store unencrypted copies or to keep encryption keys. Since they're the one giving you the key they obviously know it at some point, however briefly, and they are thus vulnerable. Forcing users to generate and supply keys just isn't user-friendly on a web-only application. The only way you can make that work, as SpiderOak did, is have the user download an application which seamlessly does all the crypto work.
[0]: https://spideroak.com/ [1]: https://www.tarsnap.com/ [2]: http://support.crashplan.com/doku.php/articles/encryption_ke...
Spideroak is for your own private storage (+ShareRoom for sharing with a group), MEGA is positioning primarily for filesharing.
Yes, they both use encryption for files without sharing the key with the service provider but that's as far as I'd go with the similarity.
Here's a list, taken from (http://www.kimpl.com/1297/secure-online-backup-file-sync-ser...) which also has some reviews.
(https://www.syncplicity.com/)
As others say, there's a difference between syncing and hosting; between levels of security; between ease of use; etc.
And obviously Tarsnap is great, for people who know what they're doing.
Mega offers everything wrapped in encryption, so presumably, his company will have plausible deniability (zero knowledge) of the files/folders that his service is being used for.
From a technical standpoint, I also believe it makes de-duplication impossible but someone with more knowledge on that subject can comment on it.
(https://www.dropbox.com/help/27/en)
> Dropbox uses modern encryption methods to both transfer and store your data.
Sure, you're right that the difference is that dropbox holds the keys and mega doesn't. But you're also ignoring the fact that Dotcom has had considerable interest from law enforcement in the past, and that some companies have cooperated with law enforcement by pushing malformed client software to some customers.
http://images.macworld.com/images/article/2012/09/spideroak_...
Nobody cares about one to one piracy.
But he is a privacy nut, has truecrypted hard drives, and was sad there was no encryption on Google Drive.
Now this has encryption, and office tools in the roadmap, I can see the excitement of a person against piracy can have!
The Guardian interview linked from the original article is worth reading.
That said, it is to launch under one single unified host in NZ.
It can happen across all cloud platforms - and has happened for many people already.
"In 3 hours it will be exactly 1 year after the US government destroyed #Megaupload. In 3 hours #Mega will be born."
edit: that'd put Mega online ~10:45am PST
Access Denied
when trying to access https://mega.co.nz. Is anyone else getting the same?"Site is extremely busy. Currently thousands of user registrations PER MINUTE." - @KimDotcom
"Wow. I have never seen anything like this. From 0 to 10 Gigabit bandwidth utilization within 10 minutes." - @KimDotcom
In the end, I think I'll just use an EncFS volume and back it up with whomever is most convenient. If MEGA gives me 50 GB of free storage, they are very convenient.
I could register and (apparently) generate a private RSA key, which was sent to mega.co.nz as part of a HTTP POST payload. I wonder if that's only used for the current session, which I guess is mandatory, but I'd like to understand more: how does the model work for sharing, for instance.
mega.co.nz = "mega conz"
I'm just wondering if it has a desktop sync like Dropbox. Now that would be MEGA.
Definitely a case of "no such thing as bad publicity". At this point, he probably has better name recognition than dropbox, before the product is even out.
Showing that you are willing to fight for your cause, despite having powerful enemies, and sticking to your mission even after your company, your home and your private life have been raided, demonstrates integrity. And integrity is probably the best publicity you can get - especially when operating in controversial industries.
I personally would love to see a Mega incubator that fosters an environment of similar challenging ideas (for example building on Mega's in-browser encryption).
That said I support the guy and will use MEGA. But double back up of sensitive files with a dropbox/skydrive/google drive.
For personal encrypted sync & backup I'd guess encrypted you-hold-the-key solutions like CrashPlan, Tarsnap, Wuala and SpiderOak are better options.
"Warning: You are using an outdated browser, which adversely affects your file transfer performance. Please upgrade to Google Chrome."
What is this bullshit? I'm using the latest Firefox. You are concerned about privacy, but you want to force me into using a propietary browser?
> However, some legacy or technically inadequate browsers require the entire file to be stored in memory for downloading (Firefox, IE10, Opera), or for both downloading and uploading (IE9, Safari 5).
At the end, the choice is yours but they are fairly warning you that the UX would be better on Chrome / ium.