3 ms·
They cannot read your files, only your password can be used to decrypt them, which is not even saved on their server. https://spideroak.com/zero-knowledge/ htt
by mathrawka 13y ago
They cannot read your files, only your password can be used to decrypt them, which is not even saved on their server.
https://spideroak.com/zero-knowledge/ https://spideroak.com/zero-knowledge/
https://spideroak.com/engineering_matters https://spideroak.com/engineering_matters
- LoganCale 13y agoIf you enter your password into a system that they control at any time, they have potential access to your files and can be ordered by the government to change their code so that it does collect your password in order to enable decryption of your files.
- WildUtah 13y agoand can be ordered by the government to change their code so that it does collect your password in order to enable decryption of your files. And they can be ordered to do so secretly with no notice, neither to company management nor to you nor to any judicial body that could review the decision. That's the lesson of Lavabit.
- kelnos 13y ago... or so they say. I do happen to trust them (and use them), but they absolutely could read your files if they want to: all they have to do is release an updated version of the sync app that does save your password when you first sign in. Or they could start saving passwords when people sign in via their website. Now, I don't believe that they'd do this maliciously (rogue employees aside), but there's always the possibility that a government agency could secretly require them to actively try to capture a particular user's password the next time they sign in.