3 ms·
Yeah, it's puzzling why SpiderOak persists in using the term "zero knowledge" to mean something entirely different from ZKPs. As far as I can tell they're the o
by bascule 10y ago
Yeah, it's puzzling why SpiderOak persists in using the term "zero knowledge" to mean something entirely different from ZKPs. As far as I can tell they're the only ones doing this too.
Especially with zkSNARKs and practical applications like Zcash, all I can think this will accomplish is confusing people.
- toyg 10y agoBecause it differentiates them from the likes of Dropbox, who can easily look into your files. What other term would you use? "Client-side encryption" is too diluted a term.
- schoen 10y agoThey tried to coin a new (unrelated) sense of this term about two years ago in order to try to explain services where the service provider doesn't have access to your data. I agree that it's confusing because of the much more clearly established technical term with a different meaning, and I don't think SpiderOak's sense has caught on outside of the company. Can anyone suggest a better term? Some people like "end-to-end encrypted" even in this context, but that doesn't really make sense for data at rest, which is almost all of what SpiderOak's products deal with. Edit: SpiderOak has had a super-hard time marketing their privacy features to people who aren't already familiar with the fairly stark distinctions in play in different access models. I'm sure they would appreciate if someone came up with a straightforward way to explain "products where the service provider doesn't have access to your data, and can't get access without your help in any circumstances because of technical constraints".
- d_theorist 10y agoSteve Gibson calls this type of design "Trust No One" (TNO), which I quite like. But I think "end-to-end encrypted" is fine and has caught on with the public to some extent.
- chongli 10y agoOf course, you can't really get to "Trust No One" level unless you build your own computer by hand and write its entire software stack from scratch. It's kind of an arbitrary distinction, otherwise.
- y7 10y agoI think client-side encryption covers it pretty well. https://en.wikipedia.org/wiki/Client-side_encryption https://en.wikipedia.org/wiki/Client-side_encryption