29 ms·
Kim Dotcom's New Mega Encrypted Cloud Storage
- dannyrosen 14y agohttp://www.spideroak.com http://www.spideroak.com has been doing this for years. Nothing new to see here.
- watty 14y agoYou're right, technically they're not doing anything groundbreaking. The difference is that they already have a huge fan base, ridiculous amounts of publicity, and much better UI and pricing than spideroak.
- AhtiK 14y agoThey are quite different: MEGA is a web-based file hosting, spideroak is a desktop app that syncs your local files to the cloud for sync&backup. Spideroak is for your own private storage (+ShareRoom for sharing with a group), MEGA is positioning primarily for filesharing. Yes, they both use encryption for files without sharing the key with the service provider but that's as far as I'd go with the similarity.
- tubbo 14y ago2gb encrypted vs 50gb encrypted...
- jedbrown 14y agoAlso, Tarsnap and Wuala.
- nick2 14y agothe free account will be 50GB.
- huhtenberg 14y agoOh, common. Encrypted online storage is nothing new, period. It's the proudly extended middle finger that makes all the difference.
- gregd 14y agoHave you actually used SpiderOak? While I have tried and tried, I find their interface (OSX and Win) to be utterly and irretrievably confusing.
- corford 14y agoWhat's confusing about it? I use it personally and also regularly set it up for most of the clients I consult for. I've never had anyone come to me and say they've found the interface confusing. It just works.
- DanBC 14y agoThere's a bunch. Some are better than others. Here's a list, taken from (http://www.kimpl.com/1297/secure-online-backup-file-sync-service/ http://www.kimpl.com/1297/secure-online-backup-file-sync-ser...) which also has some reviews. (https://www.sugarsync.com/ https://www.sugarsync.com/) (https://www.dropbox.com/ https://www.dropbox.com/) (https://www.wuala.com/ https://www.wuala.com/) (https://www.syncplicity.com/ https://www.syncplicity.com/) (https://mozy.com/ https://mozy.com/) As others say, there's a difference between syncing and hosting; between levels of security; between ease of use; etc. And obviously Tarsnap is great, for people who know what they're doing. (https://www.tarsnap.com/ https://www.tarsnap.com/)
- gregd 14y agoThere aren't a bunch. Sugarsync and Dropbox only offer encrypted transport of your files. To actually encrypt the files/folders themselves requires a 3rd party piece. Mega offers everything wrapped in encryption, so presumably, his company will have plausible deniability (zero knowledge) of the files/folders that his service is being used for. From a technical standpoint, I also believe it makes de-duplication impossible but someone with more knowledge on that subject can comment on it.
- DanBC 14y agoDropbox offers encrypted storage of files. (https://www.dropbox.com/help/27/en https://www.dropbox.com/help/27/en) > Dropbox uses modern encryption methods to both transfer and store your data. Sure, you're right that the difference is that dropbox holds the keys and mega doesn't. But you're also ignoring the fact that Dotcom has had considerable interest from law enforcement in the past, and that some companies have cooperated with law enforcement by pushing malformed client software to some customers. (http://www.wired.com/threatlevel/2007/11/encrypted-e-mai/ http://www.wired.com/threatlevel/2007/11/encrypted-e-mai/)
- thirsteh 14y agoEncrypting files at rest means nothing if the data and keys aren't separate. It's just compliance/PR fluff.
- nwh 14y agoThat application has a hilariously bad interface. Imagine how bad their backend is if they can't even add white space between their checkboxes. http://images.macworld.com/images/article/2012/09/spideroak_2012_03-293149.png http://images.macworld.com/images/article/2012/09/spideroak_...
- thoughtcriminal 14y agoPersonally, I can't wait for this. Yes, I have a Dropbox account and have for years, but I like the ideology behind this, and lately the US government doesn't seem to be all that concerned about the liberties of its citizens - or citizens of any country. I'm just wondering if it has a desktop sync like Dropbox. Now that would be MEGA.
- jpdoctor 14y ago> but I like the ideology behind this, and lately the US government doesn't seem to be all that concerned about the liberties of its citizens Definitely a case of "no such thing as bad publicity". At this point, he probably has better name recognition than dropbox, before the product is even out.
- 1337biz 14y agoIt is not bad publicity at all. In fact he has, despite his problematic past, shown the strongest commitment possible to his clients. He could have sold or left Megaupload long before things came down. He could have left the Mega idea behind and put his focus and money towards saver ventures. But instead he continues to stay dedicated to the cause he is fighting for. Showing that you are willing to fight for your cause, despite having powerful enemies, and sticking to your mission even after your company, your home and your private life have been raided, demonstrates integrity. And integrity is probably the best publicity you can get - especially when operating in controversial industries. I personally would love to see a Mega incubator that fosters an environment of similar challenging ideas (for example building on Mega's in-browser encryption).
- baby 14y agoAre you sure? I don't think I'm the only one having reservations about signing up for a MEGA account. Since his last product didn't last, what tells me that the same fate is not going to hit his new project? I can't put needed files on a product that might go down with my files someday. That said I support the guy and will use MEGA. But double back up of sensitive files with a dropbox/skydrive/google drive.
- 14y ago
- akosner 14y agoI like the logical chess game that Dotcom is playing here. Even if everybody knows that some of the storage will be used for copyrighted material, it can't be proven that ANY of it is. There are many legitimate reasons why people want secure, encrypted and private storage, so innocent until proven guilty (which can't be proven!)
- benologist 14y agoIt depends if he tries to monetize it by paying referral fees to websites indexing all the pirated stuff ... again. Nobody cares about one to one piracy.
- akosner 14y agoI wonder how much of a house of cards would be necessary to distance MEGA from such indexing sites and yet still profit from it. Dotcom did say he is interested in new business models. How new could it be?
- Jach 14y agoWell, copyright owners can still send DMCA takedown requests on links that include the decryption key. But Mega can't automatically take down copies of the data (since any copies will be encrypted by a different key), and more importantly they can't offer big copyright houses custom tools (like MegaUpload did, and Youtube does) that find and flag material for them automatically.
- jtreanor 14y agoMega's launch site (http://kim.com/mega/ http://kim.com/mega/) appears to be down. It does seem to be getting lots of attention.
- Kudos 14y agoWhile it sounds like it would be great for secure archival storage, I can't help but worry that it would disappear one day in a raid.
- jtreanor 14y ago"“Each file will be kept with at least two different hosters, [in] at least two different locations," said Dotcom." from http://arstechnica.com/tech-policy/2013/01/building-mega-ars-pre-launch-interview-with-kim-dotcom/ http://arstechnica.com/tech-policy/2013/01/building-mega-ars...
- ceejayoz 14y agoSimultaneous raids are well within the capability of US law enforcement, even overseas.
- chrisrogers 14y agoThe model is to eventually have thousands of varied hosts within the storage network. That said, it is to launch under one single unified host in NZ.
- kmfrk 14y agoEven better. It means you will treat your data like it might all disappear one day, as you should with all cloud data. It can happen across all cloud platforms - and has happened for many people already.
- speeder 14y agoMy associate is really wanting it. Not because it was Megaupload, my associate is very much against piracy... But he is a privacy nut, has truecrypted hard drives, and was sad there was no encryption on Google Drive. Now this has encryption, and office tools in the roadmap, I can see the excitement of a person against piracy can have!
- dublinben 14y agoThere are any number of cloud storage options (SpikerOak, Crashplan, Backblaze, Tarsnap, Amazon, Wuala, etc.) which offer client side encryption using a key you control. I would consider any of those before I trusted important files to this new service.
- eps 14y agoI'm getting a blank page with a simple Access Denied when trying to access https://mega.co.nz https://mega.co.nz. Is anyone else getting the same?
- seferphier 14y agosame. I can't wait until this service is launched.
- davorak 14y agoI thought they lost that domain and the forbes author was just made a mistake. All of the recent links have pointed to kim.com or kim.com/mega
- JeremyBanks 14y agoThe domain they lost was http://me.ga/ http://me.ga/
- keithpeter 14y agohttp://www.guardian.co.uk/technology/2013/jan/18/kim-dotcom-fight-internet-freedom?CMP=twt_gu http://www.guardian.co.uk/technology/2013/jan/18/kim-dotcom-... The Guardian interview linked from the original article is worth reading.
- 00dgm 14y agoFrom his twitter feed just now: "In 3 hours it will be exactly 1 year after the US government destroyed #Megaupload. In 3 hours #Mega will be born." http://twitter.com/KimDotcom http://twitter.com/KimDotcom edit: that'd put Mega online ~10:45am PST
- hcarvalhoalves 14y agoI like this guy, he's beating copyright enforcers at their own game. That's literally DRM the other way around.
- sgarbi 14y agodown for me
- cdash 14y agoHe just posted on twitter a new music video it seems. http://www.youtube.com/watch?v=Fr1feJDCjPo&feature=youtu.be http://www.youtube.com/watch?v=Fr1feJDCjPo&feature=youtu...
- WA 14y agoMEGA could be the only cloud storage I'd actually start trusting. I don't use Dropbox, I don't use Google Drive or anything else, because I'm not interested in other people being able to peep at my data. While I don't perceive Dotcom as a trustable character, his incentive to NOT store any encryption keys on the servers is much higher than any of his competitors.
- batgaijin 14y agoBut Dropbox is a YC company. Why do you need the assurance of some fancy acronym like AES?
- algorias 14y agoIs a fancy acronym like YC any better? I would trust the founders not to look at private data, but any company that has employees is vulnerable to one of them going rogue.
- WA 14y agoExactly. In addition: If on court order someone wants to access my data in the cloud, even (or especially) a YC company will follow the order. The only protection against that is that the cloud storage provider doesn't have the encryption keys.
- racbart 14y agoYC doesn't control Dropbox. Whatever trust you have in a minor shareholder, it shouldn't translate to trust for the company. There are other reasons as well: potential vulnerabilities in their software, malicious/crazy/corrupted employees, etc. Healthy need-to-know rule is enough to decide that if there's no reason your cloud provider should have access to your data, he shouldn't have it.
- TheEskimo 14y agoI do hope this is a joke. "some fancy acronym like AES"... I can't tell if this is a failed attempt to be funny through saying something so ridiculously stupid or if you're serious. There are lots of acronyms that are BS, but AES isn't one of them. It's mathematically backed and has been thoroughly tested to be strong. Dropbox being a YC company means absolutely zero other than that YC liked their idea and supported them. That doesn't give me any assurance that they won't make a mistake or that an employee won't sell my data. In fact, Dropbox, despite being a YC company, already slipped up majorly once to the point that every account was completely passwordless. You could just type in random emails at the web login and view some stranger's files. Story here: http://techcrunch.com/2011/06/20/dropbox-security-bug-made-passwords-optional-for-four-hours/ http://techcrunch.com/2011/06/20/dropbox-security-bug-made-p... On the other hand, AES has yet to slip up. My AES encrypted data will take a significant fraction of the life of the universe to crack and, YC or no, a single programmer error won't break it.
- ninetax 14y agoSo this says all files will be encrypted with RSA, doesn't that mean who ever wants to access them needs the key? Is this just not a successor to Megaupload then? How will sharing files publicly work? Or will it at all?
- jedberg 14y agoIt's all in the article. You can either send the recipient the key in a side channel or include it with the link.
- deleted 14y ago[deleted]
- racbart 14y agoYou could do that if there is a per-file key. But you'd need some client software to store and manage keys for individual files for easy exporting urls including these keys, and I read that MEGA is managed only via web (at least now).
- cdash 14y agoThis is built in as I understand it, there is a master key that is used to encrypt a key database that is stored on the server for each user.
- sgarbi 14y ago"30 Minutes until #Mega. Lets make it 5% of the Internet this time ;-)" https://twitter.com/KimDotcom/status/292682270324703235 https://twitter.com/KimDotcom/status/292682270324703235
- gregd 14y agoI was able to get my account, although the registration process bombed out on me..it still gave me my account.
- StavrosK 14y agoMy quandary: I don't trust any third-party client, and the clients I do trust are too cumbersome. In the end, I think I'll just use an EncFS volume and back it up with whomever is most convenient. If MEGA gives me 50 GB of free storage, they are very convenient.
- JimWestergren 14y agoFrom his Twitter[1]: "Site is extremely busy. Currently thousands of user registrations PER MINUTE." - @KimDotcom "Wow. I have never seen anything like this. From 0 to 10 Gigabit bandwidth utilization within 10 minutes." - @KimDotcom [1]: https://twitter.com/KimDotcom https://twitter.com/KimDotcom
- deleted 14y ago[deleted]
- teoruiz 14y agoI still have my doubts about their privacy practices, I would love to see a detailed technical article on how the actual PKI infrastructure works. I could register and (apparently) generate a private RSA key, which was sent to mega.co.nz as part of a HTTP POST payload. I wonder if that's only used for the current session, which I guess is mandatory, but I'd like to understand more: how does the model work for sharing, for instance.
- robomartin 14y agoIsn't it true that ANY web storage and file-sharing company could be raided and shut-down tomorrow? What's different between Megaupload and Dropbox or any of the others? If the Feds (and the Motion Picture industry) decide that Dropbox is hosting pirated works they could suffer the same fate, no? I am not focusing on Dropbox here. They are just a place holder for any storage/sharing service you'd care to name. I use Dropbox almost exclusively and love it. The point here is that, unless I am wrong, your data isn't safe anywhere outside your own four walls. So, if data loss is your concern, be sure to back it up locally. If you do things right it should not matter if Mega (or any other service) implodes overnight. Set yourself up to not loose anything if that were to happen. If you do that, then you can use any service and sleep well knowing that such a failure (or confiscation by the Feds) is of minimal or no consequence to you.
- rorrr 14y ago> Isn't it true that ANY web storage and file-sharing company could be raided and shut-down tomorrow? I'd say at its present state, MEGA servers are one of the least likely to be raided, considering the clusterfuck with the last raid. > if data loss is your concern, be sure to back it up locally That's a horrible advice. A company that does data storage professionally is much less likely to lose your data. If you have a house fire or a major flood, your computer and your backups will be gone. Diversification is the key to data safety. Back up both locally and online.
- robomartin 14y agoThat is far from horrible advice. And you are taking "locally" way too literally. You get to define what "locally" means. It definitely means "not trusting a third party with your important data". In my case it means that I keep three full backups of everything at three different locations and with various incremental and full-backup schedules. Old data that doesn't see a lot of activity is archived and even burned to DVD and stored in a fire-proof safe. I know that some of it is a bit extreme, but I actually take my work product very seriously and most of it represents "cubic hours" of work. I take the position that my business data is my responsibility and I store it "locally" with enough redundancy that it would take a pretty major event for a significant chunk to be lost. That does NOT mean that I don't use remote storage/backup services. It DOES mean that I operate as if they could be reduced to dust tomorrow. Which, in turn, means that I have all of the convenience some of these services offer while not having to worry too much about issues at the backup provider ruining my life.
- mylittlepony 14y ago"Mega rocks with Google Chrome" "Warning: You are using an outdated browser, which adversely affects your file transfer performance. Please upgrade to Google Chrome." What is this bullshit? I'm using the latest Firefox. You are concerned about privacy, but you want to force me into using a propietary browser?
- rozap 14y agoYou can use Chromium.
- arcatek 14y agoThere are stating in their help page that Firefox allocates as much memory as the size of the downloaded files, which is not very convenient for this kind of application. > However, some legacy or technically inadequate browsers require the entire file to be stored in memory for downloading (Firefox, IE10, Opera), or for both downloading and uploading (IE9, Safari 5). At the end, the choice is yours but they are fairly warning you that the UX would be better on Chrome / ium.
- mylittlepony 14y agoWell I don't like their tone, I don't need to be told that my browser is "outdated", especially if it's not, it works perfectly fine for basically the rest of the internet, including web dev tasks. If there is a very specific use case for which it's not the best, they should have said so. They should have checked whether I'm using IE6, or the latest FF version, and adapt their speech accordingly. I feel like an angry nerd right now, but I'm the user this time so I'm right and they are wrong.
- Endless 14y agoWhy should Mega being going out of its way to make you feel better?
- guiambros 14y agoAnd.... it's down. And it's not just me. http://www.downforeveryoneorjustme.com/mega.co.nz http://www.downforeveryoneorjustme.com/mega.co.nz
- 0xC3 14y agoHmmm... interesting use of a domain hack. mega.co.nz = "mega conz"
- nwh 14y agoI doubt it's any more intentional than the main second level domain for the Cook Islands. http://en.wikipedia.org/wiki/.co.ck http://en.wikipedia.org/wiki/.co.ck
- mahmud 14y agoOr use the GPLed Tahoe-LAFS, by Zooko (et al), a real hacker and man of unquestionable integrity. https://tahoe-lafs.org/trac/tahoe-lafs https://tahoe-lafs.org/trac/tahoe-lafs
- joonix 14y agoCouldn't they just pull the plug on all of their servers? Then they wouldn't need the keys. They could demand removal of copyrighted files, but if Mega refuses to do so, they could demand the server be taken offline until they figure out how.