Bitcasa: Infinite Storage (really?)(bitcasa.com)
bitcasa.com
Bitcasa: Infinite Storage (really?)
http://bitcasa.com/
54 comments
Well the "You are at the back of the queue, but post this link into your twitter or facebook stream and get your beta invite sooner" message after signing up for the beta didn't help with the sleazy/scammy vibe, that's for sure.
They never mentioned it was free. So it's probably pay-for-what-you-use amazon backed storage. I haven't seen anyone complain about Jungledisk using the "Unlimited cloud drive storage" tagline.
The finite part is the bandwidth you gonna get. If you can't get them uploaded, you ain't gonna get it filled.
I didn't see anything that looked like a webapp. It could be like Dropbox, right?
what would you call a service that allows you to upload an unlimited amount of files then? I honestly felt it sounded like most of "unlimited" plans - backblaze, yahoo inbox, amazon prime, etc
My problem is not the "unlimited" part so much as the way it obfuscates the fact that it achieves this by storing your files online. To a technologist it's obvious what's going on; to the average user watching this video, I don't think it's clear that this product requires Internet connectivity to function -- in a couple places, it even appears to suggest that it doesn't, e.g. the "clunky web service" line.
Understood, but I think that everyone save the most novice of all users understands that any subscription service they are paying for is not a piece of hardware. And therefore, since you cannot increase storage on a harddrive, it must go somewhere other than your computer, which implies a connected network. Am I being too optimistic?
Clearly they need to work on a better video. The disrupt showcase was much more informational on those aspects. They mentioned caches, pricing, etc.
When reading this so many red-flag warnings popped up that I could not decide if they were deluded or frauds. I will give them the benefit of the doubt and simply guess that they are deluded regarding the storage savings they will eventually realize via de-dupe. Given that the founding team includes a bizdev guy, a marketing guy, and a sysadmin/ops guy I am guessing that they can put together a nice pitch and powerpoint, have some easy answers to the operational problems of competing in this space, and have a lot of hand-waving answers to the harder technical problems. The latter problem will probably end up killing them unless we are just seeing a PR dump in preparation for a pivot to being just another online backup company.
One major fly in this whole "de-dupe" claim is that it will probably not even work out for them even if they did have some magic sauce to dance around the de-dupe/crypto conflict others have noted. The problem is that the files which users actually care about and want to back up are not the common files but the ones which make their data unique; it is not the mp3s or hollywood videos that matter, it is the data/content that each person has created that matters. If my disks crashed, my online and offline backups were corrupted, and I needed to rebuild my system I could get the common OS files in a hour, the mp3s and videos would take a few weeks of passive torrenting, but the pictures, home videos, and personal documents would be gone forever. It is these files that matter for a backup services, and they are not going to be something that you can de-dupe even if they were not encrypted.
Back when the term "de-dupe" did not exist and convergent encryption was something we were inventing before the term existed the thought was that a backup service employing these techniques would enjoy a massive savings in storage costs -- it turned out that people cared less about backing up the data that was easy to de-dupe and original data was a much larger portion of what users uploaded than we expected. This was back when pics were a meg or two and personal video was low bitrate, now that even a mobile phone is dumping multi-meg pictures and you can get a HD video camera for a hundred bucks I cannot imagine how anyone would convince themselves that de-dupe is going to make any significant difference to the operational costs of such a service.
One major fly in this whole "de-dupe" claim is that it will probably not even work out for them even if they did have some magic sauce to dance around the de-dupe/crypto conflict others have noted. The problem is that the files which users actually care about and want to back up are not the common files but the ones which make their data unique; it is not the mp3s or hollywood videos that matter, it is the data/content that each person has created that matters. If my disks crashed, my online and offline backups were corrupted, and I needed to rebuild my system I could get the common OS files in a hour, the mp3s and videos would take a few weeks of passive torrenting, but the pictures, home videos, and personal documents would be gone forever. It is these files that matter for a backup services, and they are not going to be something that you can de-dupe even if they were not encrypted.
Back when the term "de-dupe" did not exist and convergent encryption was something we were inventing before the term existed the thought was that a backup service employing these techniques would enjoy a massive savings in storage costs -- it turned out that people cared less about backing up the data that was easy to de-dupe and original data was a much larger portion of what users uploaded than we expected. This was back when pics were a meg or two and personal video was low bitrate, now that even a mobile phone is dumping multi-meg pictures and you can get a HD video camera for a hundred bucks I cannot imagine how anyone would convince themselves that de-dupe is going to make any significant difference to the operational costs of such a service.
Maybe it's like the yahoo mail infinite mailbox. They just severely limit the bandwidth in/out, but storage is infinite. Given an infinite amount of time...
I have to say that I find it a 'little' sad that the entire post reads like a Press Release, touting 'client side encryption' like something new and exciting and two thirds down it's revealed that CrunchFund is an investor.
Poor author didn't even know when she interviewed them.
Poor author didn't even know when she interviewed them.
I'm confused, they mentioned at techcrunch disrupt that they are able to offer infinite storage because they are deduplicating data. Fine. But they also said that they will be doing client side encryption. Contradiction - encrypted data cannot be deduplicated.
What if in the header of the file they put an md5sum that is not encrypted?
I don't think that would represent a data leak, and you could then dedupe based on md5sums...
I don't think that would represent a data leak, and you could then dedupe based on md5sums...
But only one of the two users could decrypt the block - useless.
downvoters: If I encrypt a plaintext, and you encrypt the same plaintext, we'll have different ciphertexts. If we detect that we encrypted the same plaintext, how do we deduplicate? (Also, I would consider that a leak.)
downvoters: If I encrypt a plaintext, and you encrypt the same plaintext, we'll have different ciphertexts. If we detect that we encrypted the same plaintext, how do we deduplicate? (Also, I would consider that a leak.)
[deleted]
I encourage everyone in this thread to read up on convergent encryption.
http://research.microsoft.com/apps/pubs/default.aspx?id=7421... http://www.ssrc.ucsc.edu/Papers/storer-storagess08.pdf
http://research.microsoft.com/apps/pubs/default.aspx?id=7421... http://www.ssrc.ucsc.edu/Papers/storer-storagess08.pdf
I encourage anyone who is thinking of implementing convergent encryption to read "Convergent Encryption Reconsidered" from the tahoe guys: http://www.mail-archive.com/[email protected]/msg089...
(tldr; there are serious security/privacy vulnerabilities with convergent encryption)
(tldr; there are serious security/privacy vulnerabilities with convergent encryption)
Client-side encryption does not exclude server-side decryption, ie: only encrypt it on the wire, not the storage device.
Like Dropbox.
Like Dropbox.
from their faq:
Your Data Is Secure
Bitcasa encrypts your data before it is sent to the cloud. It is actually impossible for Bitcasa to access any of your data for any reason.
"Client-side encryption" generally means that only the client can decrypt the data. Unfortunately, if you forget your key, you can't reset your password to recover your data.
> Contradiction - encrypted data cannot be deduplicated.
That's correct; there might be a middle ground that's yet to be explored and proved secure.
Check previous discussion here: http://news.ycombinator.com/item?id=2570538
That's correct; there might be a middle ground that's yet to be explored and proved secure.
Check previous discussion here: http://news.ycombinator.com/item?id=2570538
wouldn't deduplicating encrypted data still work but your hit rate would just be a lot lower. you would have to work on a block instead of a file level but in theory you could dedupe file blocks that had been encrypted, because either way in the end its just bits.
Or is the assumption that with encrypted data you are so incredibly unlikely to see hits that its not worth doing...
Or is the assumption that with encrypted data you are so incredibly unlikely to see hits that its not worth doing...
if a file is encrypted correctly, you should not be able to compress it or match it to the same file encrypted a second time.
I understand that, but couldn't two different files encrypted with two different keys theoretically share some identical blocks. Obviously this is way less likely than two unencrypted files sharing blocks but still it could happen.
They really pushed the "infinite storage" point in their presentation. But didn't they mention something about predicting which files to cache before they are requested? I would have liked to see more focus on that. Otherwise, it doesn't seem much different from dropbox, which is more established.
We will see. Actually some backup companies also have such claims on storage (e.g. http://www.crashplan.com http://www.backblaze.com)
Well this is also backed by CrunchFund.... we would see (seen via TCDisrupt)
Well this is also backed by CrunchFund.... we would see (seen via TCDisrupt)
Er, I think you meant http://www.backblaze.com/ . The link you've got goes to a somewhat NSFW site.
I guess somebody got it fixed for me, thanks.
My last time visit on mozy I didn't see "unlimited" offerings.
For, uh, small values of infinity? Or something?
I find that I don't run out of storage on my computers any more, so perhaps I'm not their target audience. Best of luck competing in that space, though--it seems pretty crowded already. :)
I find that I don't run out of storage on my computers any more, so perhaps I'm not their target audience. Best of luck competing in that space, though--it seems pretty crowded already. :)
Yeah, it would be funny if the "service" is just to rent a Drobo attached to a PogoPlug :)
Wait, I should do that...
Wait, I should do that...
Just a reality check on your landing page: your #1 asset is a vimeo embed, which causes several problems:
The "Learn More" link is more informative, but still, I think you really badly need a designer.
1) I'm on roaming 3G, I'm not paying that much to know what you're about
2) Flash is blocked by default so all I see is a black square
3) You're royally pissing on blind/disabled people.
Besides, the color scheme / general theming is generally sub-par and difficult to read.The "Learn More" link is more informative, but still, I think you really badly need a designer.
From what I understand the concept is something similar to Dropbox, except instead of simply syncing files between the folders on different computers where all the files are physically present on each, it focuses on remote access (possibly with an AFS-like caching layer).
And by infinite, they probably mean "as much as you are willing to pay for," or, during the beta, "as much as you want until it gets ridiculous."
And by infinite, they probably mean "as much as you are willing to pay for," or, during the beta, "as much as you want until it gets ridiculous."
[deleted]
[deleted]
The problem with all these online storage services is uploading your data.
At my 1 mbit uplink it would take 97 days of non-stop uploading to upload 1TB. That's if my ISP doesn't ban me.
At my 1 mbit uplink it would take 97 days of non-stop uploading to upload 1TB. That's if my ISP doesn't ban me.
Ive got an "infinite stotage device" called /dev/urandom.
It does take a while to wait for your data to come back out :)
It does take a while to wait for your data to come back out :)
Even if /dev/urandom gives 10Gbps, a 1kb file would take 2^1018 Seconds, which is 1.4E688 years. That's well over the length of the universe (1.3E10)
I respect their need to find a sexy way to sell a cloud-storage-and-sync product, especially since it's an increasingly crowded space, but this seems a bit sleazy.