9 ms·
Following to their architectural design, they do not get access to any encryption key and no key leaves user device in unprotected form. Is not this enough to b
by Jivanyan 10y ago
Following to their architectural design, they do not get access to any encryption key and no key leaves user device in unprotected form. Is not this enough to be advertised as "zero-knowledge" service provider?
- federicobond 10y agoNo, that's called end-to-end or client-side encryption. Zero-knowledge is a property of a certain class of methods that allow one party to prove to another that a certain statement is true, without revealing anything else about it.
- geofft 10y agoThe term "zero knowledge" has a specific technical meaning in cryptography: https://en.wikipedia.org/wiki/Zero-knowledge_proof https://en.wikipedia.org/wiki/Zero-knowledge_proof Passing encrypted data through a storage device isn't a "zero-knowledge protocol" in a cryptographic sense, it's just normal cryptography.
- danbruc 10y agoAs a technical term zero-knowledge has a very specific meaning [1] and is not what they are using. Here it is just a marketing term and may confuse people knowing about the technical meaning but that is certainly only a very small fraction of the population and so it is probably not a huge issue. [1] https://en.wikipedia.org/wiki/Zero-knowledge_proof https://en.wikipedia.org/wiki/Zero-knowledge_proof
- bad_user 10y agoThat's kind of bullshit though, you can't claim 2 common words from the English language in order to only describe a concept many of us don't understand. I'm a software developer, have been for 15 years, I've stayed fairly awake in college during my cryptography classes, have implemented hashing functions (mentioning this because such a history already place somebody in the 0.01%) and I've never heard of "zero knowledge proof". Not surprisingly, the link you've given is about a phrase with 3 words in it, not 2. And while I've always been annoyed about overloads of "open source", at least that's a words association that you won't hear from non-technical folks and that wasn't in use before OSI happened. And even so, note that OSI couldn't trademark it.
- Ar-Curunir 10y agoJust because people don't know the term doesn't mean cryptographers don't know the term; any cryptographer with any formal cryptography training has heard of the term, and it's not used to refer to any other concept in the cryptographic literature. The usage of the term matters when it'll be cryptographers reviewing the work; almost every thread about SpiderOak I've seen calls them out on misleading marketing. Hardly good for PR.
- carussell 10y agoYour link is for zero-knowledge proof. They aren't claiming anything in the realm of proofs, zero-knowledge or not. If "zero-knowledge" implicitly meant "zero-knowledge proof", there would be no reason to ever use the latter phrase. Zero-knowledge is an adjective. It's a modifier. It's the "proof" part in "zero-knowledge proof" that's important in describing what it is. "Zero-knowledge" is a property of the method employed. The irony is that, wrt the original comment, it's end-to-end encryption that would be a misleading and misapplied label. I'm not affiliated with this company and I've never even used this service before, and yet it's immediately clear what zero-knowledge means in the context of a cloud storage provider: you never need divulge your keys, so the question of whether you trust your provider or not is moot. Back when Firefox Sync first launched, I was chasing the idea of referring to it and any similar service as "zero-trust" systems. But building a service and referring to it as "zero-knowledge cloud storage" is totally acceptable.
- danbruc 10y agoNot sure whether I was clear enough, but I understand both sides of the argument. It is a very specific technical term and the zero-knowledge proof Wikipedia article states that zero-knowledge is the name of one of three properties that zero-knowledge proof have to satisfy, on the other hand it is also a nice, catchy and probably understandable marketing term if you want to express that you know (almost) nothing about the users' data. Developer me would certainly prefer technical accuracy but we all know that users certainly could not care less what is the technically correct name for the thing. So I don't care at all whether they call it zero-knowledge or not, they are not trying to trick anybody into believing they are doing zero-knowledge stuff in the cryptographic sense. I actually like zero-trust but I can see how this could easily be interpreted in the wrong way, should or must not be trusted instead of need not be trusted.
- Ar-Curunir 10y agoZero knowledge means a very specific thing in cryptography, and is used exclusively to refer to zero knowledge proofs; in all of cryptographic literature over the past 25 years I have not seen any other usage of "zero knowledge". Either way, this system isn't "zero knowledge", even if that term were well defined for this situation; you leak file sizes and access patterns.