3 ms·
I had the same feeling when reading the copy on the site. I looked for an explanation of what they mean by the statement, but couldn't find one. Google led me
by no_protocol 10y ago
I had the same feeling when reading the copy on the site. I looked for an explanation of what they mean by the statement, but couldn't find one. Google led me to a Spider Oak page that seems to use the terminology in a similar manner [1].
I have a hard time even accepting this definition of "zero knowledge' on its own, separate from the existing cryptographic one. Wouldn't the host at least know things like the size of the encrypted data? Time it was sent? Etc.
[1] https://spideroak.com/features/zero-knowledge https://spideroak.com/features/zero-knowledge
- whamlastxmas 10y agoFile size and date sent is probably only useful if someone is specifically targeting you, and it's virtually guaranteed that the only person who wound target someone specifically and also be able to make use of that data is a government agency. In that case they'd be able to monitor your data at an ISP level anyway, making it moot. It doesn't look like Spideroak takes bitcoin payments anyway, making this even further moot. Anyone serious about privacy against state actors wouldn't use it.
- coldwaterq 10y agoI don't agree that only government agencies would care. For example, anyone on open wifi can be easily targeted. So anyone doing something at a university could be targeted. I would imagine that some corporation would be interested in something from a university enough to try this.
- no_protocol 10y agoUseful or not, I consider the boldface statement > we know nothing about the encrypted data you store on our servers misleading, since they do know some things about the encrypted data.
- whamlastxmas 10y agoI strongly support SpiderOak but I agree with you. Even if they don't keep logs of that stuff, they could or could be ordered to do so. They obviously think the "ordered to do so" part is a real threat because they dissuade used from logging in through the website.
- willvarfar 10y agoMetadata is often more useful than the message, and sometimes can expose the message. For example, a collaborative editor had better not send each key press to the other editors else timing attacks can reconstruct probable text fragments etc.