3 ms·
I can't understand how people trust (or even care about) server-provided encryption. There's no guarantee they or their friends can't open it on their servers.
by certainly_not 13y ago
I can't understand how people trust (or even care about) server-provided encryption. There's no guarantee they or their friends can't open it on their servers. Unless you use your own solution, their encryption only provides protection in transit, against unaffiliated third parties.
- rdl 13y agoLink encryption is good, and it's helpful to ensure the only attack vector is the service provider itself, not sub-contractors or someone being stupid and throwing away drives. That said, Dropbox has done a pretty good job of lying about how much security they offered users in the past. But someone providing a service like this with a reasonable security policy which is openly communicated to the users is still better than no security policy.
- tmikaeld 13y agoWhen it comes to zero-knowledge encryption, it is hard to know how their implementation holds up without external audits. This is the same for other encryption applications (google Truecrypt audit). EVault, Wuala, Tarsnap, SpiderOak, Norton Zone, KeepVault, Jungle Disk, ElephantDrive, CrashPlan, Carbonite, F-Secure, Handy Backup, IASO Backup, MediaFire, MEGA, OwnDrive, TeamDrive etc.. ..all provide Zero-Knowledge encryption for their cloud backups, i think OVH should be able to at least the same.
- drdaeman 13y agoWhat's the point of "supposedly zero-knowledge encryption" if you can't even be sure it's there? If you care about your data security, you'd better consider there is no encryption in such cases. If you don't care - why ask for encryption at all?