4 ms·
I think most of the responses here regarding the crypto are missing the point. It doesn't matter if the key is not totally random. It just has to be good enough
by phpnode 14y ago
I think most of the responses here regarding the crypto are missing the point. It doesn't matter if the key is not totally random. It just has to be good enough so that they can plausibly deny that they know anything about the file contents. It is their attempt to absolve themselves of responsibility for the copyright issues concerning the content. It is not about making your files more secure.
- res0nat0r 14y agoHow is this new service supposed to be viable like the last MU? If the point of this "encryption" is supposed to provide plausible deniability, then the whole point of distributing warez via this site "legally" will have to be that the decryption keys are kept secret or underground. But for this site to be popular enough to allow for downloads supported by ad revenue, then the file links and decryption keys will have to be widely distributed to drive traffic. If someone files a takedown notice with a file and decryption key that proves the data contained therein is copyrighted then won't MU be in the same boat they were in previously?
- phpnode 14y agothey could be doing something as crazy as putting the key in the "share this" URL. If they put it after the fragment then it doesn't get sent to the server and they can continue to deny having the ability to read file contents. Someone did a "Show HN" with a site that did something similar a month or two back. Presumably mega then don't offer a site search but instead rely on google to index warez forums with links to the site that include the decryption key. I don't know. Edit: found the site that did this: http://news.ycombinator.com/item?id=3852649 http://news.ycombinator.com/item?id=3852649
- samwillis 14y agoYep, that was me. I strongly suspect that this may be what he is up to. It occurred to me at the time that there may be a way of doing it with files. Ultimately I shut down the site as it got very little traction.
- 4ad 14y agoI don't think this encryption is supposed to provide plausible deniability in the most general sense. Stuff was DMCA'ed from megaupload all the time, but that was never a problem. There were many many many uploads of the same data and you could always find a working copy. There was a lot of friction because some people wanted all copies to be deleted, not just the link removed. This encryption allows for plausible deniability against deduplication. Mega can't possibly know what are all the copies of some content, so even if they comply with DMCA requests as before, nobody can force them to delete all provided copies.