5 ms·
https://bytejail.com/pricing https://bytejail.com/pricing What is the advantage of this over SpiderOak? https://spideroak.com/solutions/spideroak-one https://
by fweespee_ch 11y ago
https://bytejail.com/pricing https://bytejail.com/pricing
What is the advantage of this over SpiderOak?
https://spideroak.com/solutions/spideroak-one https://spideroak.com/solutions/spideroak-one
> SpiderOakONE is the leading private backup solution and is 100% Zero Knowledge. Get a ton of space for only $12 a month.
To me, it seems like a more expensive version.
- CiPHPerCoder 11y agoAt a glance: SpiderOak offers encrypted backups. This is a good thing. It doesn't specify how it's stored on their end (presumably because it doesn't matter to the end user). So that's an unknown. Bytejail offers encrypted anonymous backups (via Tor Hidden Service) and uses a TahoeLAFS backend. My understanding of TahoeLAFS is that it's excellent. So if you're security-conscious, Bytejail would seem like a better choice. (I'm not familiar enough with SpiderOak to comment on their offering in detail; I can only really go off the page you linked.)
- fweespee_ch 11y agoFyi: https://spideroak.com/manual/zero-knowledge-explained/ https://spideroak.com/manual/zero-knowledge-explained/ Its local encryption then copies the resulting blob to SpiderOak. Lose your password, lose your ability to decrypt as you need it to decrypt locally.
- CiPHPerCoder 11y agoYeah, I know. Both services offer that. Bytejail uses X25519 + Xsalsa20Poly1305. SpiderOak uses RSA-2048 + AES-256. (Is it AES-256-CTR + HMAC-SHA2 or is it AES-256-GCM? That page doesn't specify.) Bytejail uses scrypt. SpiderOak uses PBKDF2-SHA256 with 16384 iterations. My earlier comment was saying: Bytejail uses TahoeLAFS on the backend after receiving encrypted blobs. SpiderOak uses ________? Again, to clarify: This isn't a crticism of SpiderOak. I just literally don't know what they are doing from the pages people have linked to in this thread.
- Freaky 11y agohttps://spideroak.com/features/private-by-design https://spideroak.com/features/private-by-design - "SpiderOak uses AES256 in CFB mode and HMAC-SHA256."
- CiPHPerCoder 11y agoThanks. Not sure how I feel about CFB but that did answer one of the two big questions the other page didn't. :)
- gballard 11y agoI don't know much about Bytejail or their offering; but I'd say one major, non-technical difference is that Bytejail is a German company with servers located entirely outside of the US. In theory, this makes search-and-seizure of customer data subject to German statutes, which are currently much stronger than US law in terms of privacy. Take a look at SpiderOak's privacy policy, under the "Disclosure" section (https://spideroak.com/policy/privacy-policy https://spideroak.com/policy/privacy-policy): >SpiderOak's policy is to notify a user of a request for their personal data stored on our servers prior to disclosure unless prohibited from doing so by statute or court order [e.g. U.S.C. § 2705(b)]. That would be NSLs.
- nickpsecurity 11y agoExactly. You can't trust any security company operating in U.S. legal system. I say that as an American doing INFOSEC work. The company must be located in and at least jointly-owned by a privacy friendly jurisdiction. Little police corruption helps, too.
- Veratyr 11y agoNo logging, multiple locations, not subject to NSLs or US law, audited codebase, based on open source software (Tahoe-LAFS) and it's not SpiderOak (I see that as a feature given my experience with their client and support).