Google tests encryption to protect users' Drive files against government demands
news.cnet.com
news.cnet.com
But if you have a big container (say, 1GB or so), it has the drawback of re-syncing the file back-and-forth. And if you have multiple devices (including mobile, etc), this would easily became a nightmare.
That's a bummer. I love TrueCrypt for local encryption of filesystems and containers, but I wish I could use as a lightweight, on-the-fly, encryption of files. Particularly dropbox and other cloud-based storage.
I use trucrypt + dropbox combination because DropBox has delta sync, but your way makes Drive also a good option.
http://news.en.softonic.com/google-chat-history-can-no-longe...
> One of the features of Hangouts that was really emphasized at I/O, was that you will no longer have to worry about losing anything. Chats are kept, and everything you share, like photos, is put in folders and stored.
Let us help you by monitoring you better and recording everything you do. For your convenience and protection of course.
You know, I didn't like them. Now I despise them. They said that with a straight face. They could have just you know, not say anything, or say Facebook is doing all this stuff we can't fall behind we need this data on your because we want to target ads better or we have to comply with government regulations. That's fine. I understand that. But telling people how this is for their convenience is really demeaning.
I see your intention here, but I think you've stepped out of touch with the vast majority of users here, and I don't mean the "people just want to share their lives on facebook, privacy be damned" kind of way.
"Chats are kept, and everything you share, like photos, is put in folders and stored" really is a feature that people want. Not being able to set a default for do/don't save all chat history should be fixed, but what you quote really is for convenience.
I search over my gtalk history all the time, as just as much useful information is in there as is in my email. I don't use the Google+ picture auto-upload, but I do use the Dropbox one, so that all the pictures I take with my phone are automatically uploaded to my dropbox folder and available on all of my computers. Those things are really convenient, and I love not having to have to think about them; they're just there when I do need them. I don't see how that could be possibly construed as only motivated by ad revenue and government regulations.
What needs to come along with those features:
1) easy to disable/enable with good granularity (per feature, per contact, altogether, etc)
2) possible to secure client-side if I want to
3) government needs to demonstrate probable cause to get warrant to get access to what is not secured client-side
4) I need to be notified within a reasonable amount of time of a warrant being served
none of those things preclude these kinds of "nothing is ever lost" features.
> Or using third-party OTR plugins (with real encryption)
> by replacing gtalk XMPP with Google Hangout?
Has this actually stopped working for you? On my account, Gtalk still works fine with XMPP, including OTR chats in Pidgin.If you need XMPP and OTR, run Openfire on a VM. I just deployed this internally at work and we love it.
I recommend Spider Oak as a replacement for Google Drive.
Also, don't forget Bittorrent Sync.
from: ... <support@spideroak.com>*
date: **** 2013
subject: Re: [SOS #xxxx] A question about zero knowledge
Sorry for the delay in getting back to you. Zero-knowledge
applies only when using the SpiderOak client. When logging into the
website with your password, you are giving the primary encryption key to
our servers. We work hard to ensure that this key is kept safe (for
instance, by only keeping it in memory and never writing it to disk),
but to maintain absolute privacy, you should use only the client.Spider Oak: I wish there were some open source cloud client similar to True Crypt. Something that were really easy to use, working on every system and open source. Spider Oak's client seems to be still mainly a closed source product.
The whole thing currently sits on top of BitTorrent although I suspect I'll end up writing a forked implementation at some point to support some extensions I'm working on.
Active, dynamic syncing is great for some kind of data but not so important for others, and I feel like that's the hurdle that needs to be overcome. More interesting to me is painless, fast, robust, and configurable sharing of relatively static data. (Some versioning may be included but it won't be a first-class system.)
It is libre software and cross-platform. A number of front-ends address the issue of ease-of-use.
[0]: http://duplicity.nongnu.org/ [1]: http://duplicity.nongnu.org/features.html
cperciva posted why Tarsnap was more secure and cheaper than Duplicity a while back:
Of course it would still need a security review.
Just like 1984.
Which is part of why the NSA guide to securing a machine recommends that you decide whether or not you actually need the camera and microphone, and if not, you open the case and physically cut the cables.
In addition to being a signals intelligence agency, NSA is also responsible for IT security for the federal government (and, to some extent, the nation). While it's possible they leave some of the more interesting tricks out of the public versions of these guides, their publication is in line with NSA's advice and assistance on open-source cryptography, etc.
How hard can it be to manufacture a product with an off-switch?
If a users asks for something to happen (like a Skype call) it should just happen. To end-users, having multiple points at which the functionality they want can be switched off is just frustrating, and it costs manufacturers call center time and customer satisfaction.
The paranoid can tape over cameras and cut mic cables if they feel it's really necessary.
You really might want to consider whether "slavery" is the appropriate word for switches implemented in software.
It's been a long time since we had the big red IBM XT flip switch.
Even my calculator doesn't have a physical off switch.
1) The location of their servers in Norway; I'm based within the EU, but quite far from Norway, and Norway doesn't scream great connectivity to me in the same way Britain, France, or Germany does;
2) Their FAQ seems a bit slapdash, e.g. "What kind of servers are my data stored on? Linux";
3) As with most other storage providers, there is no mechanism preventing the provider from accessing your files, or sharing them with third parties, no matter how much you trust them.
Couldn't they just use a hand-wavy encryption like a caesar cipher that meets the legal requirements without actually making storage any harder?
http://www.syncdocs.com/how-to-set-up-google-drive-encryptio...
On Windows BoxCryptor classic creates a virtual drive which you use to access the files. The actual files are stored as encrypted in Dropbox/GDrive folder. BoxCryptor can also encrypt file names.
Benefit from this approach compared to for example TrueCrypt is that works really nicely with the syncing features of these cloud storage systems as the files are still stored as individual files.
I'm going to give insync a look, though I'm not thrilled about paying for something to access cloud storage that I'm not paying for.
Oh and as other said, NSA can force them to do what Microsoft did.
It would be also nice to have option where my data is begin stored (again for a fee if necessary). I would like mine in their Finnish data center.
Besides, Google has local company in each country that runs business there.
You shouldn't have to pay a company to make sure they don't share your data. That is, in essence, what you're suggesting: you pay google, they encrypt your data and when the government comes a-knocking, it's safe. It's like a hack in a broken system
However, I think you somewhat sidestepped hannibal's point. My impression was that he was saying that just by putting your files in drive for google to mine, you are effectively paying google. If they encrypt your files, it's akin to them discontinuing their monthly fee (or whatever) for the service.
So sure, if you're already paying a fee for a service then maybe you shouldn't need to pay extra for the luxury of privacy (make no mistake, privacy is a luxury these days), but Google encrypting their revenue stream means you are substituting the ad fee for the encryption fee. Seems fair to me.
I would like to have clear option of being fed advertisements and being profiled for profits and paying for service.