|
|
|
|
|
by bdhe
5505 days ago
|
|
That's not true. As is, in a lot of crypto problems, there are powerful workarounds that require a lot of work.
See here for one idea: http://news.ycombinator.com/item?id=2461713 Unfortunately, this starts to become a cat-and-mouse game. |
|
So that all the RIAA has to do is provide a sample mp3 and then DropBox can see who has AES(F, H(F)) stored. Only the files with user generated unknown content can remain mysterious to DropBox, widely used files cannot.
And since you use aes(f, h(f)) you can't change the encryption key on any particular file.
And since the client software needs to use the local DB and since they have the list of files you uploaded, they have most of the plaintext known if they want to try to decrypt the DB maliciously.
But if they do want to, they can leak the password you type in to themselves anyway.
Also, how would this scheme interact with DropBox's differential upload and revision tracking feature?
ZFS does encryption and deduor too, so yes it is possible, but secure trustable ecrypted DropBox where they also do the encryption part?