In 2013 Lavabit shut down because a US agency was demanding access to its private SSL keys and basically the deets on whatever users the US was interested in. Lavabit shut down rather than give the US that access.
Yet, this means that Lavabit had the ability to give the government access to the data it stored for its users.
In light of this, a service called SpiderOak claims to have a Zero-Knowledge encryption mechanism that means it is unable to access user data even if it wants to. While some companies say they wont access your data, SpiderOak claims that it can't.
My question essentially boils down to the truth of this claim. What evidence is there that SpiderOak, even when pressured by a random agency or otherwise compromised, actually can't divulge the data it stores?
Also, I understand that zero-knowledge is a mathematical possibility (although I don't claim to understand exactly how that works). I am more interested in how an outside user can trust the company. Who has audited it? What credibility do they have? The software appears proprietary, so how do I know they didn't make some major mistakes?
Aucun commentaire:
Enregistrer un commentaire