Home Page › Forums › General Chat › PSA: Mega encryption has been broken
- This topic has 16 replies, 9 voices, and was last updated 4 years, 3 months ago by
NobunagaOda.
-
AuthorPosts
-
June 27, 2022 at 9:56 AM #1824262
I haven't seen anyone talk about this on the forum yet, so I thought it would be good to let you guys know, since pretty much every Zone member uses Mega.
Their encryption has been broken and if anyone wants access to your files, they can theoretically get it now.
You don't really need to worry about that though, since the majority of Zone-member accounts will not be worth it for any hacker to break into. To break into an account takes a lot of effort and time.
I know some people care about this more than others, so here I am just spreading the word.The people feeling affected by this know what they ought to do.
You can read up on the paper here:
https://mega-awry.io/On another note: when using Mega to store your (very) private data, encrypt it before uploading it. Not only for Mega, but any cloud storage.
I won't be going into the "if you have nothing to hide, why do xyz" debate. I can only suggest to take the advice. You never know what might happen in the future.Personal suggestions, all open source:
Windows: Cryptomator (no Linux support, has some annoying issues with OneDrive) or cppcryptfs (latter has cross-platform compatibility with gocryptfs and droidfs)
Linux: gocryptfs
Android: Cryptomator, droidfsHave a great day!
June 28, 2022 at 2:26 AM #1824592Good to know, but the only thing on my Mega are Daz assets.
June 28, 2022 at 4:13 AM #1824610Personally I don't give my MEGA files obvious names and there's nothing to stop us from sharing induvial file decryption passwords here rather than Mega's now-defunct client encryption.
June 28, 2022 at 6:26 AM #1824626You never know what might happen in the future.
And there I'm happy with
June 28, 2022 at 9:00 AM #1824687I was thinking the other day about alternative schemes to host files, that would be impervious to takedowns and other vandalism.
Then it came to me...B L O C K C H A I N
Why not encode asset data into an immutable public blockchain record, much like NFTs, or Etherium or Bitcoin or whatever. Once it's in there, it's in there. Anyone with a client and a key can access the contents of such a vault, or "asset wallet" if you will. Anyone could add an asset, anyone could read out that asset, but only the one who added it could modify it. Since it's distributed (decentralized), there's nobody to complain to or harrass to have something scrubbed.
So, instead of downloading from a monolithic server like Mega, you would fire up your client and feed it a key, much like you'd do with a torrent. It's probably trivial to add
a layer that ties the transaction to a domain, so that other sites don't scrape your wallet (i.e. repost your links). You'd have to access Zone-deposited assets from Zone, etc.June 28, 2022 at 9:27 AM #1824707there is an "unnatural" awareness of "privacy" on the Internet: Even a stupid "Buy a loaf of bread, I forgot this..." WhatsApp message needs to be encrypted!
I'm tired of prime numbers, of "onion" algorithms, like the Tor network, the shit of the "Blockchain" and the sublime occurrence of NFTs, worthy of millionaire cretins...
When quantum computers are available to the public, it will be another stupidity to enrich the same as always.
"Encrypt" is synonymous with "hide": Only real sins are hidden. I am not talking about religions, but about ethics and morals.
If there were, for example, a squirrel that took all the nuts on half the planet and hid them in a remote cave with 30 different keys, without a doubt, it would be a case study for humans: "This squirrel is crazy", would be the conclusion. However, a human makes him and we put him out as "person of the year" in Forbes magazine and we kiss his ass. 😀June 28, 2022 at 11:30 AM #1824778That's the price you pay for technological advancement.. when you go about trusting and putting your personal stuff in the clouds that belong to someone who says "We're the most secure place for your data".. this is what you can expect.. and I'm not talking about just Mega..
June 28, 2022 at 12:02 PM #1824786“Encrypt” is synonymous with “hide”: Only real sins are hidden.
I completely disagree with this. You can hide secrets that are not "sins" such as industrial formulas etc. Also, just because someone don't like a camera in his bathroom, it doesn't mean he has something nefarious to hide!
there is an “unnatural” awareness of “privacy” on the Internet: Even a stupid “Buy a loaf of bread, I forgot this…” WhatsApp message needs to be encrypted!
There is a reason this has happened. It's because corporations started to sell personal information without consent, so that "your information" can be used against you to bombard you with a thousand useless ads, if not for something more nefarious. Trust is broken, at this point.
June 28, 2022 at 1:21 PM #1824807Having nothing to hide doesn't mean one should live in a house made out of glass.
June 29, 2022 at 10:07 AM #1825344@legolas18 Forgive me! I forgot that the countries keep the state secrets in Mega, as well as the terrorists, drug and arms traffickers, and the payroll of the members of "The Bilderberg Club", those who rock the cradle...
And don't talk to me about "business secrets or formulas", I'm an industrial designer and you don't know about the paperwork, lawyers and notaries that a project of mine has to go through with "patents, industrial models, etc..." before showing it to a business...
Next month, I will be 55 years old. I'm not a lammer...
What I have no doubt is that philosophy books are not your thing, nor that I'm going to spend 20 years snooping whatever garbage there is in Mega... 😀
@NobunagaOda Remember architect Mies van der Rohe and the "Farnsworth House"?... 😀June 29, 2022 at 10:39 AM #1825357@abad !
I forgot that the countries keep the state secrets in Mega,Please stop the condescending style. I was talking about "secrets" in general, not keeping secrets in MEGA.
you don’t know about the paperwork, lawyers and notaries that a project of mine has to go through with “patents, industrial models, etc…” before showing it to a business…Again, stop being presumptuous. You have no idea where I work, so how can you tell that "I have no idea"?
Next month, I will be 55 years old. I’m not a lammer… What I have no doubt is that philosophy books are not your thing,You have no idea who I am, and as an industrial designer "that you claim to be" means what? that you have a better understanding on philosophy? that you have showed you have not much experience with, since you took my generalization and tried to prove it wrong by using a specific case? Is that what you use to win arguments? Personal attacks?
Also, why make it personal and attack me, when I just disagreed with something you said? You know who does that? People that don't have an intelligent argument. Perhaps being 55 hasn't taught you as much as you think it did.
June 29, 2022 at 6:40 PM #1825517@Abad: Sure, I know the one... and I sure wouldn't live in it 😀 just the hailstones hazard lately... I'd rather have a well fortified hom which an be, depending on the situation, raise higher in case of flood or hidden below ground level in case of annoying people. Practicality 😀
June 29, 2022 at 8:36 PM #1825557@littlepleasures
I'm sure you're right about that, but I'm postulating there has to be some sort of way to "float" immutable data in a decentralized "cloud-ish" form that can be selectively accessed.
We need some more engineery types to put some braincells together and figure out how that could work.
On the other hand, if such a thing were possible, it might unleash a terrible beast upon the copyright world. Imagine a virtual service with no governing authority that could not be cajoled into deleting content...
Did I bump my head, or is that devil horns I feel popping out there? 🙂June 29, 2022 at 10:31 PM #1825576... or, we just repost, repost, repost until someone drops dead of exhaustion or boredom. 🙂
<edit>
@littlepleasures
My thought is far from the torrent model, though that crossed my mind at one point, it's not good for all the reasons you mention.Not sure where you're going with all the encryption angles, the point is not to hide anything, indeed, literally anyone, including the White Knight, should be able to access the data without a private key or any other such encumbrance. My whole "dream" is simply one of decentralization, such that all the bits of some data are scattered, (somewhat like a torrent), but have a persistence that is independent of at-will users (very much unlike a torrent). Any encryption involved would strictly be some sort of self-embedded tracking (again, unlike a torrent) and possibly an ability for the original author to modify such data, but no one else. Then, the onus of takedown falls not on any single host, but on the originating author... everyone knows where Mega lives, but nobody knows who Anon is.
You did hit upon a detail I didn't mention, which is distribution of chunks across persistent hosts. I don't think that there would be many, or even more than a single host required to author a file; simply that the data be broken up into many parts and hosted as separate uploads. This could be done automatically by a client-side user tool, and in multiples, having a similar effect of RAID striping. The author's own private key would allow uploading and editing, while a public key would work against the embedded mask that would figure out which files on the host belong to the data. Likely, this can all be handled by the same user tool or script (both authoring and retrieval), and being a client-side process it would not require any resources from the Blog server other than to expose the public key for a given download (much like it currently exposes a URL to the data). Downloading would fetch a complete copy of the data, without exposing the actual source(s) of that data. You simply get a key, turn it, and automagically get a file.
That's the basic idea, anyway. There's surely some glaring flaws in the concept, but it's something to run with in any event.
Every castle began as a dream in a king's heart.June 30, 2022 at 8:30 AM #1825768@legolas18
I apologize: I never wanted to attack you, or anyone. I don't think I'm superior either: It was to try to explain the bureaucratic obstacles of any patent... I don't claim my opinion, but rather I think there is a misinterpretation of my words from the beginning.
I think, speak and write in Catalan (very different from Castilian, which is what you know as "Spanish": Other languages are spoken in Spain, such as Galician, Bable, Euskera...) Mentally I translate it to " Castilian", and Google translate does what it wants... (Google still doesn't understand Catalan or Japanese very well...). Besides, I use a language of expressions that are perhaps untranslatable. Like a "street languague...", slang to understand each other...
With the "philosophy books", it is an expression used, locally, like "find the three feet of the cat": To complicate an issue. (Again I doubt you understand me..)
It's like a translator's nightmare: Taking James Joyce's "Finnegans Wake" and trying to come out with "head held high."
I'm very sorry: I'll try to be more concise and not "get into reading philosophy books". 🙂 -
AuthorPosts
- You must be logged in to reply to this topic.




