6 ms·
Firstly, the submission title is not a quote (for anyone wondering). Secondly, how else do you expect the process to work? They don't hold your key, so to decr
by jonathonf 11y ago
Firstly, the submission title is not a quote (for anyone wondering).
Secondly, how else do you expect the process to work? They don't hold your key, so to decrypt the data you have to provide the key. The data is held on their server, and to decrypt it to send to you they have to decrypt it. So you have to provide the encryption key at some point? Once you have your data restored, you can change the encryption key.
- ianlevesque 11y agoAn obvious alternative would be to decrypt the backup locally instead of entering the key into their website.
- noja 11y agoYou decrypt locally.
- dogma1138 11y agoLocally or even during download in the browser mega.nz sends you encrypted blobs which are decrypted using the download auth key after the download is verified they use html5 storage and JavaScript to achieve this.
- jdenning 11y ago>Once you have your data restored, you can change the encryption key. Unfortunately, even if you change it, they still have access to the files encrypted with the previous key. Also, it's generally recommended to test the restoration of your backups, otherwise you can find yourself in a really bad spot if/when you need to restore - IMHO, this definitely includes verifying that there wasn't an error in the encryption/decryption process (i.e. changing the key would necessitate testing decryption with the new key, which requires giving them the new key).
- jonathonf 11y agoThank you all for prodding my brain in the right direction. :)