Mega Overtakes Rapidshare, DropBox
zeropaid.com
zeropaid.com
Is this not the equivalent of judging Windows usage based on visits to microsoft.com?
I created a Dropbox account (which I do use) a couple years ago, and last week I visited the site for the first time in almost as long as I've had the account.
A word of warning to you, since you don't access the site often: your password expires, and you'll need access to your email account when it does.
My laptop semi-died last week (it's not actually dead, but I couldn't get it to boot at the time), so I used my girlfriend's to order a new one.
I keep my KeePass database in my DropBox for just such occasions, so I tried to log into Dropbox's web interface to retrieve it and access my account on the computer retailer's website. Dropbox accepted my password, but told me I couldn't continue until I changed my password, which required clicking a link they had sent to my email account.
Unfortunately, the password to my gmail account is also in KeePass, and is an incomprehensible mess of generated gibberish that I don't know, so I couldn't get in. I had to reset my Google password using an email account that is apparently on file with Google, in order to reset my password with DropBox, in order to access my retail account with the laptop vendor.
I don't know if this would have been easier had I known about DropBox's two-factor authentication before this, or if maybe I could have installed DropBox on my girlfriend's laptop and got in that way without needing to reset anything, but I ended up burning half an hour on this because I didn't know I had to keep my password constantly up to date on their website.
It seems like an obvious thing to do, but for something like Dropbox which is just "always there" on your local machine, it's an easy thing to forget.
https://krebsonsecurity.com/2012/07/dropbox-password-breach-...
I'd delete my comment now, if I were still able to.
Personally, I don't think I've been back to the Dropbox website since I reset my password!
My reply was merely a "mea culpa", and the note about removing the previous comment was more about removing inaccurate information than about saving face.
I've corrected that assumption now.
Some people rely too much on "one password" solutions, because of security, etc
But it's very easy to lock yourself out of everything. Very easy.
The best place for keeping important passwords is still my head.
Sure, you can use password management solutions, just keep a backup (piece of paper, secondary means of logging, etc)
I think that a software password manager (regularly backed up) with a master password stored in a secure (offline) location is the best solution.
And don't forget to test the backups periodically, and check the master password
I can't think of a better way to get someone with real crypto cojones to fix their crypto missteps. Power to Kim and what he´s doing. 50GB for free is amazing.
The really good hackers are likely out getting paid good money for their work, and won't necessarily have time to poke at this for uncertain reward. There might be sufficient value in the publicity associated with finding flaws (especially while it's getting lots of media attention right now), but a competition/challenge is rarely a good economic choice for the potential entrants.
A bug bounty programme might be useful as a supplement to a rigorous security audit, but the issues discovered so far seem to be things that could have been identified by reasonably competent netsec people, indicating that such an audit either didn't happen, or wasn't acted upon.
But there is the thing - mega is not a good service - too much false promises. Seems like a honeytrap for infringers. There are ways to design it better with better guarantees for user privacy.
1. I will get as many backblaze pods as I can.
2. Client will mostly be the same with few differences - the encryption will be symmetrical (AES probably), with randomly generated key from high quality entropy. This key will never leave the client. File names will be encrypted too. It will be bundled with the file and uploaded in some blob For directories - they can be tared first before encrypted. So the only thing that I will see as a host is file size.
3. There will be some more keys that will be generated and uploaded - keep alive and kill switch. keep alive must be given on regular intervals or content expires. The kill key will delete the file on the server and as many of the logs as legally possible, end of story.
4. The server returns the unique url.
5. You get some text on your screen that will give 3 urls - kill url - keep alive url - decrypt key - safe download url (http://something/url) will be asked by the page to give key. Decrypt will be on the client too. - unsafe download url (http://something/url#key)the javascript will begin decryption immediately but if someone intercepts the url - he will have the key.
5. Premium accounts will be given on scratch cards or bought with bitcoins. Donations will be accepted anyway but won't give benefits.
6. .onion address for upload
7. Outgoing bandwidth - the speed of the downloads for all but premium accounts will be function of the donations received the previous day.
8. Everything will be open , and the community will be allowed to audit the systems.
That is in general details.
http://cl.ly/image/0q2e462p1V2Y
Dropbox is used primarily via client apps, those figures must be less than 10% of it's actual usage.
"If the launch day signups and traffic were something to shout home about, after the surge of media attention that Mega garnered over the next few days from sites like ourselves,"
...but ends up supporting its claims with Alexa traffic ratings...
"it only got stronger and now we’re at a stage where Mega has almost broken into the top 100 sites in the world."
A complicated interactive site is of course much harder to mirror than a bunch of magnet links.
https://mega.co.nz/#!jFlzGQiZ!CL2dMi5IAYLUp3ZQ5JS7nmW0sYtudf...
Let's give it a few days and then we will see.