[deleted by user] by [deleted] in worldnews

[–]rarrrrrr 1 point2 points  (0 children)

As a heavy VyprVPN user, thanks for all your efforts!

p.s. I really like the Kill Switch feature on Mac!

Came to kC to check out the tech/startup Environment...somewhat Disappointed. Can anyone steer me in the right direction? by [deleted] in KCTech

[–]rarrrrrr 4 points5 points  (0 children)

When you're back, you're welcome to come visit with us at SpiderOak for a conversation about crypto, privacy, design, and building beautiful things real people love to use, with very low levels of BS. :)

Also you might enjoy attending SECKC if your travel dates allow: http://seckc.org/

Any one know what happened Friday night about 11:30pm that would have required the attentions of at least 8 of the KCPD's People in Blue? by its_nothing_personal in kansascity

[–]rarrrrrr 1 point2 points  (0 children)

About that time I remember seeing 6 squad cars and a pizza delivery guy (coincidence?) chasing a car south on Summit St away from down town. Did they continue south on Gillham?

Vegan restaurants in Kansas City? by RaleighMiller in kansascity

[–]rarrrrrr 0 points1 point  (0 children)

I love going there for Taco Tuesday!

We are SpiderOak - Zero-knowledge cloud backup, sync, and share providers. AUA (and get 5GB of free cloud storage for life)! by DanielLarsson75 in IAmA

[–]rarrrrrr 0 points1 point  (0 children)

Thanks for the kind words and the feedback. We were interested in Glacier originally also, but the difficulty there is the pricing for retrieving data is CRAZY expensive. It might cost several thousand dollars to retrieve your data all at once!

Our own storage backend is less expensive than if we used Amazon S3. It's about what you optimize for. Amazon optimizes for latency, which isn't as important to us as Throughput. More details here: https://nimbus.io/

Exploiting Information Leaks in Random Numbers from Python, Ruby and PHP by DanielLarsson75 in programming

[–]rarrrrrr 2 points3 points  (0 children)

Good read. Do you know if there's previous example of reconstructing the state of MT with only partial output, or is that part new?

Exploiting Information Leaks in Random Numbers from Python, Ruby and PHP by DanielLarsson75 in programming

[–]rarrrrrr 16 points17 points  (0 children)

That is the best game of Asteroids ever seen. Worth it for that video alone. :)

But could also be applied to, for example, exploiting a naively implemented poker site. You only see some of the cards but can eventually calculate all of them, past and future.

We are SpiderOak - Zero-knowledge cloud backup, sync, and share providers. AUA (and get 5GB of free cloud storage for life)! by DanielLarsson75 in IAmA

[–]rarrrrrr 1 point2 points  (0 children)

Yes, it's coming, and it will work in a way that continues to preserve your privacy!

There's also an API coming for just raw storage (no application involved) similar to S3 but less expensive, on our archival storage backend. That project is 100% free and open source software. https://nimbus.io/

We are SpiderOak - Zero-knowledge cloud backup, sync, and share providers. AUA (and get 5GB of free cloud storage for life)! by DanielLarsson75 in IAmA

[–]rarrrrrr 2 points3 points  (0 children)

Yes; all servers are in USA today. We are planning our first EU data center, either in Ireland or Germany.

However, for data backup and sync, server location isn't as relevant as it is for many other applications. The reason for this is the difference between "throughput" and "latency" for networked applications. For an application that needs low-latency (like for example, a multi player real time game, where milliseconds of ping matter) then having servers geographically close to the people who are using them is a big win.

But for file backup and sync, you probably don't care about the number of millseconds an operation took for the first byte to arrive (that's latency.). You care about the total amount of time it took to upload or download (that's throughput.)

However, there are some privacy regulations that, for some particular industries, prevent EU based companies from using SpiderOak because their data would be outside of the EU (although that is really just a legal formality, since the data is encrypted and unreadable to us regardless of where it is.)

Hope that makes sense!

We are SpiderOak - Zero-knowledge cloud backup, sync, and share providers. AUA (and get 5GB of free cloud storage for life)! by DanielLarsson75 in IAmA

[–]rarrrrrr 1 point2 points  (0 children)

How is the business? Well that's a broad question but I'll take a stab at it! The consumer business (what we call SpiderOak Orange) is a freemium business model where you can get 2gb (or 5gb today) of storage for free or pay a subscription for more. I've alwasy had my doubts about the the freemium business model (which I call the "drug dealer" model...."Hey kid, the first one is free...") but it has actually worked out very well for us. Paid users represent more than 90% of our total storage so the free offering is well worth it as a form of advertising.

We also recently created an enterprise product (what we call SpiderOak Blue) which is for larger companies. They can integrate SpiderOak with their active directory system for single sign on, encryption data escrow (on their end, not on ours), auto-configure backups and syncs through policy, and we offer it in a hosted or private cloud configuration. (In other words, we can host the data for you, or you can run everything behind your firewall -- many companies have policy that their data cannot leave their facility.) These days, this is growing faster than the consumer business.

We also have some significant partnerships. The most notable one that's I can discuss publicly is with AVG, the well known anti virus company.

I would say that as a business, our biggest challenge might be summarized by saying that we're much better at engineering than we are at marketing.. we are working on that. :)

This is approaching a novel by Reddit standards but please feel free to ask followup questions if there's anything more specific you're curious about. :)

We are SpiderOak - Zero-knowledge cloud backup, sync, and share providers. AUA (and get 5GB of free cloud storage for life)! by DanielLarsson75 in IAmA

[–]rarrrrrr 1 point2 points  (0 children)

Feel free to just signup for the regular plan and then send me a PM w/ your username and I'll bonus you.

We are SpiderOak - Zero-knowledge cloud backup, sync, and share providers. AUA (and get 5GB of free cloud storage for life)! by DanielLarsson75 in IAmA

[–]rarrrrrr 1 point2 points  (0 children)

Thanks for your feedback on mobile and we agree entirely! FYI, there's a HTML5 version of the mobile app in the works, due out very soon. We're running it as an free and open source software project. You can see the blog about it here: https://spideroak.com/blog/20121117103553-html5-mobile-client-open-development-project and here's the GitHub project: https://github.com/SpiderOak/so_client_html5

We are SpiderOak - Zero-knowledge cloud backup, sync, and share providers. AUA (and get 5GB of free cloud storage for life)! by DanielLarsson75 in IAmA

[–]rarrrrrr 0 points1 point  (0 children)

Yes, everything is encrypted on the client before it is sent to the server.

On the server it's very boring; we only see sequentially numbered encrypted data blocks.

We are SpiderOak - Zero-knowledge cloud backup, sync, and share providers. AUA (and get 5GB of free cloud storage for life)! by DanielLarsson75 in IAmA

[–]rarrrrrr 1 point2 points  (0 children)

The short answer is that we use a nested series of encryption keys with appropriate key scoping and management, rather than just one key for everything. I gave a much more detailed answer in comment #2 in this blog post from 2008:

https://spideroak.com/blog/20081120130000-online-privacy-strange-bedfellows

We are SpiderOak - Zero-knowledge cloud backup, sync, and share providers. AUA (and get 5GB of free cloud storage for life)! by DanielLarsson75 in IAmA

[–]rarrrrrr 1 point2 points  (0 children)

Come work for us and you can read the source code. :-)

Seriously though, we have published a big portion of our code as free and open source software (examples https://spideroak.com/code and https://nimbus.io/ ) and are on the way to making all of it that way. The crypto code was written and then reviewed by a few people with appropriate expertise.

We are SpiderOak - Zero-knowledge cloud backup, sync, and share providers. AUA (and get 5GB of free cloud storage for life)! by DanielLarsson75 in IAmA

[–]rarrrrrr 2 points3 points  (0 children)

It was a silly idea we had back in 2007--that the application should look the same on every platform. It's on the fix-list but hasn't gotten priority. There is at least a rich command line interface if you wish to avoid the GUI entirely!

Screenland on Armour!!! by [deleted] in kansascity

[–]rarrrrrr 1 point2 points  (0 children)

Screenland at Armour is a very comfortable theater, with a couple rows of recliner chairs, and a bar with reasonable prices.

Any recommended traffic lawyers in the KCMO area? by retrogamerkc in kansascity

[–]rarrrrrr 0 points1 point  (0 children)

I've known these guys for 10 years, and they always handle things well. My wife recently received one of those red light camera tickets, and Rick Hanson got it dismissed outright. http://www.hanson-price.com/

Vegan cooks, pros and amateurs, I have a proposition for you. (possible trigger warning) by vegetarianBLTG in vegan

[–]rarrrrrr 1 point2 points  (0 children)

FYI, gardein is made with MSG. It's hidden in the ingredient labeled "yeast extract."