The problem is, somehow they know if two people upload the same file even though this should be impossible if they do bullet proof client-side encryption.
This does make Mega anything but "cryptographically safe"
The problem is, somehow they know if two people upload the same file even though this should be impossible if they do bullet proof client-side encryption.
This does make Mega anything but "cryptographically safe"
"Fact #1: Once this feature is activated [deduplication], chunk MACs will indeed be stored on the server side, but they will of course be encrypted (and we will not use ECB!). Fact #2: MEGA indeed uses deduplication, but it does so based on the entire file post-encryption rather than on blocks pre-encryption. If the same file is uploaded twice, encrypted with the same random 128-bit key, only one copy is stored on the server. Or, if (and this is much more likely!) a file is copied between folders or user accounts through the file manager or the API, all copies point to the same physical file."
So no, they don't know that two different users upload the same file, unless the key used for encryption is the same, which is almost impossible in practice.
I don't know how secure mega is, but deduplicating encrypted data is possible.
"Secure" isn't boolean. Although convergent encryption will prevent people from accessing your secret data, it does have different security properties: Mega would be able to determine whether you have a particular file, which they cannot with the current system.
MEGA actually doesn't have the key, except for files of which they already have an unencrypted copy (since the key is derived from it).
They used to claim that your data was inaccessible without your password, but this was always a lie.