Tag Archives: privacy

A Toast To Privacy at SxSW – #TakeBackYourInternet


SxSW Panel Discussion on Net Neutrality.

SpiderOak raised a glass to privacy at the 3rd Annual “Take Back Your Internet” party on Monday, March 16th. The free event, presented by GoldenFrog, was open to anyone and everyone at the SxSW Interactive Festival. Guests enjoyed free drinks, music and the discussion of Net Neutrality.



SpiderOak co-sponsored the event along with 14 other proponents of privacy. Thanks to the CDT and the Electronic Frontier Foundation, guests had the opportunity to talk directly with experts on the topic of Internet regulation.

The panel discussion addressed the battle for an open, yet competitive Internet that respects user privacy. The five experts examined the recent proposals by the FCC and how those regulations will affect the future of the Internet.

  • Marvin Ammori – Ammori Group and Affiliate Scholar at Stanford Law School CIS
  • Edward Henigin  – CTO of Data Foundry
  • Chip Pickering – CEO of Comptel
  • Gigi Sohn – FCC Special Council for External Affairs
  • James Waterworth – Vice President, CCIA Europe

Everyone seemed to agree that there needs to be a balance when it comes to regulating ISPs. “We need both competition and Net Neutrality rules,” said Ammori.

SpiderOak encouraged guests to get involved in the fight for privacy. We enjoyed handing out some swag – our new ‘Privacy Matters’ stickers and custom CamPatches (to cover your camera on your computer so no one can watch you).


SpiderOak SxSW CamPatch Swag

Increasing Transparency Alongside Privacy – 2014 Report

As we’ve stated in Transparency Reports since 2012, privacy continues to be at the root of all we do at SpiderOak. Every new product and feature is designed to fit tightly alongside our Zero-Knowledge privacy commitment. And we continue to understand how transparency plays a role in overall privacy.

Unlike overall trends, SpiderOak has enjoyed a fairly private year. Below, please find our latest Transparency Report for all activity over the last calendar year – from January 2014 through December of 2014. The report is as follows:


We are proud to stand behind our commitment in keeping our users informed of any and all activities involving their data and the constant protection of their privacy. Our relationship with the privacy advocates and other organizations will always improve our outreach and understanding so that our supporters will benefit from a fully transparent and open environment. As always, we greatly value your thoughts and feedback so please don’t hesitate to send further thoughts or questions anytime.


At the end of last year, the Pew Research Center canvassed thousands of experts on their predictions on privacy. When asked whether they believed there would be a widely accepted privacy infrastructure by 2025, many said no, stating that privacy is destined to become a ‘luxury.’ Kate Crawford, a professor and research scientist, had this to say,

“In the next 10 years, I would expect to see the development of more encryption technologies and boutique services for people prepared to pay a premium for greater control over their data. This is the creation of privacy as a luxury good. It also has the unfortunate effect of establishing a new divide: the privacy rich and the privacy poor.”

Read the full report.

SpiderOak believes privacy matters. It’s a right, not a luxury good, and therefore should be available to more than just the affluent. We are committed to bringing affordable privacy solutions to the cloud.


This leads us to announce the first pricing change we’ve ever made since we started (2007). Now get more space for less money with these three new storage plans.


To learn more about this change, how to sign up or switch plans, check out the FAQs below.

With Zero-Knowledge,
The Team at SpiderOak

=== FAQs ===

Q: This is awesome. I’d like to switch from my current plan to a new plan. How do I do so?

A: Just follow these steps:

(1) Log into the desktop application and choose ‘Buy More Space’. Alternatively, you can go to your Account page and select ‘Upgrade Plan’.
(2) Select plan size, frequency, and then click ‘Next.’
(3) Once you’ve reviewed the change, ‘Submit Order’ will complete the switch.

NOTE: You will be billed a prorated amount immediately. By switching to a new plan, you are purchasing an additional year or month of storage starting the date you make the switch which is why you are being billed immediately.

Q: Cool! I’ve been waiting for a more affordable plan to become a paid SpiderOak user. How do I sign up?

A: Welcome! We’re happy to have you join our community. You will be given 2 GB of free storage when you create your account. To upgrade to one of the larger plans, click the ‘Buy More Space’ button to choose the plan you’d like and enter your payment information.

Q: Actually, I’d rather stay on the plan I currently have. Do I have to switch?

A: If you’re happy, we’re happy. If you are a current user, you can stay on your existing plan.

Q: My current plan is more expensive so I’d like to switch. Will I receive a refund for the difference?

A: Your renewal date becomes the date you switched plans. When you move to one of the new plans, you will either be prorated or not charged at all for the first year. Refunds will not be issued.

Q: Oh no! I just signed up last week. Can I move to a better plan?

A: Yes, please see the first Q/A listed.

Q: I’m on an Unlimited (or any other discounted) plan. Do I have to switch?

A: No. You are welcome to stay on your current plan.

Q: Will you still offer an education discount?

A: We now offer a 25% discount for all .edu accounts. We also now offer a 25% discount for .org and .mil accounts.

Q: I have a .edu / .org / .mil account. How do I get 25% off?

A: If you create your account with a corresponding email address, you will automatically be able to choose the discounted plans on the ‘Buy More Space’ page. If you did not use this email address when creating your account, you can edit the address associated with your account. Once this change goes through, you’ll be able to see the new plans.

Q: Will you still run other promotions?

A: We are really excited about our new pricing but there will be promotions in the future as we’ve always done.

Q: Can I sign up from my mobile device?

A: You must sign up – or make any adjustments to your account – through the desktop application.


Personal InformationBelow is a list of 10 notable breaches that left hundreds of millions of people and their personal information at risk this year.


SNAPCHATJanuary 2014 – The supposedly private photo and video messaging app was hacked near the first of the year resulting in phone numbers and usernames of up to 4.6 million accounts being posted to public forums like Reddit.com and downloaded by a website called SnapchatDB.info. The security gap was due to user data being stored in plain text and the lack of the basic security measure of rate limiting. Later in the year, a third party vendor, Snapsaved.com, announced their servers were hacked which resulted in a breach of over 200,000 accounts and thousands of photos and videos made public.

eBAYMay 2014 – In late February or early March, more than 145 million users login credentials and postal addresses were exposed due to a cyberattack on eBay’s database earlier in the spring. The corporate network was breached when hackers compromised employee credentials that were reportedly encrypted with presumedly a weak algorithm or stolen decryption keys. Though initially confused, the company later confirmed that no financial or credit card information was compromised. Criticized for not responding appropriately or in a timely manner, the company slowly urged users to change their password and to not reuse their old password across other sites.

HOME DEPOTSeptember 2014 – Though the Department of Homeland Security warned retailers of their systems potentially being compromised, Home Depot didn’t become aware of their attack until September when 109 million records were leaked, including 56 million credit and debit cards and 53 million email addresses. Hackers gained access to in-store payment systems and stole data off the company registers during point of sale. The stolen financial information was sold on underground cybercrime sites. Facing 44 civil lawsuits in the U.S. and Canada, Home Depot has offered twelve months of credit monitoring to its customers. This attack came after a series of earlier security breaches by Home Depot employees who allegedly stole personal information of some 30,000 individuals.

iCLOUDSeptember 2014 – Backed up nude photos of Hollywood celebrities and many others were leaked due to a “brute force” access of targeted iCloud and Find my iPhone accounts. The hack, popularly known as “Celebgate,” included the posting of photos on 4chan which quickly spread throughout the internet. Though Apple denied the breach, reports of it knowing about the security hole as early as March were released.

SONYNovember 2014 – Sony’s systems were hijacked in late November with initial threats of releasing secrets if monetary demands weren’t met. Warnings were made against the release of “The Interview.” Days later, it was reported that personal and financial information of over 47,000 celebrities, freelancers, company executives, and current and former employees was leaked. Some of the information obtained was from an Excel file without any password protection. The damage also led to the postponement of showing “The Interview.” Now confronted with a class action lawsuit for not securing its computer network and protecting confidential information, Michael Lynton, CEO, said the company has not given in to the demands of the hackers.


JPMORGANSeptember 2014 – Over the summer, hackers gained access to data on more than 76 million account holders. Names, addresses, phone numbers and emails of customers who use the company’s online financial services were obtained. Information on an additional 7 million small businesses was also accessed. Security experts have reported that breach could have been avoided by a fix to a server that was apparently overlooked.


UNIVERSITY OF MARYLANDFebruary 2014 – One of the University of Maryland’s records database suffered a “sophisticated” attack at the first of the year with names, Social Security numbers, birth dates, and university ID numbers stolen from over 309,000 students, staff, and alumni. No records were altered but a copy of the information was made. A year of free credit monitoring was offered by the University.


USISAugust 2014 – US Investigation Services, a U.S. Homeland Security contractor that is responsible for more than 21,000 background checks per month for government employees suffered leak of personal information that affected more than 25,000 employees of the Department of Homeland Security, U.S. Immigration and Customs Enforcement, and U.S. Customs and Border Protection units. This was also the same firm that vetted former NSA contractor, Edward Snowden, and Navy Yard shooter Aaron Alexis. Exposed information included birth dates, family names and addresses, Social Security numbers, as well as health, education and criminal history.

USPSSeptember 2014 – More than two-dozen servers at the U.S. Postal Service came under cyber attack with blame being placed on state-sponsored Chinese hackers. More than 800,000 employees and 2.9 million customers were left vulnerable. Names, birth dates, Social Security numbers, addresses, dates of employment were some of the information obtained. It took two months to develop a response and mitigation strategy before shutting down the threat.

NATIONAL OCEANIC AND ATMOSPHERIC ADMINISTRATION (NOAA) – September 2014 – The U.S. weather service’s satellite network critical to forecasts, warnings, and disaster planning was hacked by the Chinese. Though cybersecurity teams responded immediately, officials did not notify authorities until late October. It’s unknown as to whether classified information was accessed.The system was deemed vulnerable due to a serious lack in security measures. Around the same time, systems at the U.S. Department of State and the White House were also hit.

More and more people are giving away their personal information for the enjoyment of smart devices or even without realizing it. SpiderOak urges you to take privacy seriously. Here are several tips to protect your data:

Password Management

  • Make sure your passwords are strong (no personal information, common words or sequences, make them long, use special characters when possible).
  • Do not use the same password for multiple accounts.
  • Password protect all your devices.
  • Consider a password manager.
  • Use two-factor authentication when available.


  • Use WPA2 encryption when setting up or using Wi-Fi.
  • Use whole-partition or whole-disk encryption on your devices.
  • Encrypt sensitive information before storing or sending.


  • Use security lockout feature.
  • Consider installing remote wipe.
  • Only download apps from reputable vendors (Windows Phone Store, Apple Store) to reduce the risk of receiving a malware-laden version.
  • Turn off location services, GPS, Bluetooth, and Wi-Fi until you need these services.

Privacy Policies & The Web

  • Know what information you are giving access to. If it’s not information critical to the function of the app or service, consider passing.
  • Since much of user information is sold for advertising, use social networks at your own risk.
  • Disable 3rd party cookies.

Credit Monitoring

  • Consider monitoring your credit year round.
  • Restrict access to your credit report if you are at risk of identity theft.


Supporting Reset the Net & Free Software for End-to-End Encryption

SpiderOak Supports Reset the Net and free software for end-to-end-encryption June 5Today, June 5, just a year after one of the most significant leaks in U.S. history by Edward Snowden, SpiderOak joins Reset the Net and hundreds of thousands of others to protect our privacy and freedom from government mass surveillance.

Our CEO, Ethan Oberman, had this to say about Snowden and the campaign:

The Snowden revelations not only raised the level of awareness around privacy but also intrinsically changed the way people think about their online presence. It is wonderful that there is more awareness around this issue and even more wonderful to see the advancements that companies have made in the past year, especially around data encryption. The Reset the Net campaign will help drive the dialogue forward, leading to a future in which we are able to set new, higher standards for privacy. We are proud to support this campaign and honored to participate in the worldwide movement toward a more free and secure Internet.

Here are some ways to better protect yourself against mass surveillance…


These free tools let you talk, chat, and text with privacy.

  • Adium & Pidgin for private (OTR) chat over Gtalk, Facebook, Yahoo, MSN, XMPP / Duck Duck Go and others
  • Textsecure and Redphone for Android and iPhone (we hope), for private SMS and voice calls
  • HTTPS Everywhere for browsers
  • GPGtools and Enigmail (as a bonus for more sophisticated users)
  • TOR (as a bonus for sophisticated users or those with anonymity needs)

(One important note on the inclusion of Pidgin, Adium, and OTR: if you believe you may be the specific target of surveillance, these aren’t the tools for you. Pidgin has had a large number of remotely exploitable vulnerabilities recently, and auditors looking at the code believe there are likely to be many more. Still, these tools are effective against passive mass surveillance, and they’re unusually easy to use.)


  • If you’re already a SpiderOak user (free or paid), get your additional 5GBs by sending an email toerin[at]spideroak.com with the subject ‘Reset the Net 5GB’. You MUST include your username in the message. (I will collect usernames and apply your 5GB in July, no later than July 11). 
  • If you don’t have a SpiderOak account, sign up for a new SpiderOak account and enter the promo code resetthenet. You should have 5 free GBs! If you have any issues, send us a note at support@spideroak.com.
  • If you’re a completely new SpiderOak user, sign up for a new SpiderOak account and after you download the client, choose ‘BUY MORE SPACE.’ Then choose ‘UPGRADE PLAN’ and select the plan you want. Enter the promo code resetthenet for your 33% off! Enjoy.
  1. In the client choose ‘BUY MORE SPACE’, or in the web login, go to your Account page and select “Upgrade Plan”
  2. Choose YEARLY and type in promotional code resetthenet
  3. Finally, select “Next” and “Submit Order”
  4. Congrats! Enjoy your 33% off.

*If you already have a paid account, you will have to complete this payment process. However, your account will pro-rate. PayPal users will need to cancel their existing subscription and create a new one.


We need you to build privacy into your apps! It’s the only way to make privacy scale. Check out Crypton. It’s the first application framework that provides a foundation for building ‘Zero-Knowledge’ cloud products. It allows developers to provide customers a truly private storage and collaboration environment with no access to unencrypted customer data, without having to rely on 3rd party security layers or post development hacks.

Finally, we encourage you to watch this video to learn more about Reset the Net. Support the movement on social media by sharing calls for greater privacy and security under the campaign hashtag #ResetTheNet.

EFF Recognizes SpiderOak For Having Your Back

The Electronic Frontier Foundation (EFF) just released it’s annual “Who Has Your Back?” report honoring our efforts – and others – on the legal and privacy front of protecting our users.

Of the six criteria used to assess a company’s practices and polices, SpiderOak received five of the six. According to the EFF, “SpiderOak earns 5 stars in this year’s report. It has demonstrated a strong commitment to transparency around government data requests and respect for its users’ privacy. Specifically, SpiderOak requires a warrant for access to content, gives notice to users when their data is sought by the government, publishes a transparency report detailing government data requests, and publishes its law enforcement guides. In addition, it has publicly opposed mass surveillance.”

It goes on to say, “While SpiderOak does not receive a star for fighting for user privacy in courts, this does not reflect badly on the company: Many companies do not have an opportunity to challenge an overbroad government demand or may be barred from discussing their legal challenges.”

Who has your back 2014

We have not had the occasion to defend any of our users’ rights in court. We have not been bound by secrecy of gag orders, nor imposed by court orders. In any of these cases, we would comply with the law. As our users know however, we do not have access to our users’ plaintext data. Furthermore, should we ever get the opportunity to fight for our users’ privacy in court, we would – without hesitation – do so.

Here is the complete report.

Router Security In the Cloud: Enterprises Seek Data Protection for Remote Workers

As router security becomes an increasing concern, companies with remote workers are seeking data protection in the cloud.
Image Source: Flickr User Cisco Hardware at Router-switch.com

For many enterprises, security has become a chief concern in the light of hacking, the spread of malware, and international cyber wars. The latest in the litany of worries over data safety comes from news of 300,000 compromised routers. While many enterprises operate on a much bigger scale than the small office and home office (SOHO) routers that were recently attacked, the growing popularity of enabling mobile workforce and work from home policies jeopardizes sensitive company data, due to the relative insecurity of such commonly used routers. Instead of scaling back worker mobility, enterprises can still take advantage of on-the-go work and work from home solutions by securing important corporate and consumer data in a private cloud service.

Continue reading

Generational Risk: Millennials & Data Security

IT, Finance, & The Threat to Data Safety.
Image Source: Softchoice

Millennials are typically seen as the go-to generation for all things tech-related. So it may come as a big surprise that recent surveys indicate that lax generational views toward data security could jeopardize the safety of your enterprise’s data. This flies in the face of the recent trend of reverse mentoring, in which younger workers share their tech habits to older workers. When it comes to bad habits, such practices could cause entire organizations to adopt unsafe data storage and syncing techniques, leaving sensitive corporate information open to attack or leakage.

The best way to protect such data is through strong internal systems and the adoption of secure storage and sync services. A recent survey put out by Softchoice is changing the way enterprises view their Millennial workers. According to the research, 28.5% of 20-somethings have their passwords kept in plain sight. This is in comparison with 10.8% of Baby Boomers. So it’s clear that the common wisdom that younger generations are inherently more data-secure falls flat on its face. The survey also found that the lack of secure password storage went hand in hand with syncing sensitive files to unprotected devices for the convenience of working from home. As Millennials are more likely than other generations to push for mobile or work-from-home options, companies need to find secure solutions to handle this trend without putting their data at risk.

Continue reading

Tomorrow is ‘The Day We Fight Back’ against mass surveillance

In Matt’s Damon’s AMA on Reddit last week, he was asked:

Hey Matt, your amazing monologue about the NSA in Good Will Hunting is probably more relevant today than it was when the film was first released. How did you come up with that scene, and are you at all surprised by the revelations on the NSA from the information released by Snowden? 

Here is the clip from Good Will Hunting:

Matt’s reply:

“Well, the first thing to that monologue is it’s safe to say that is the hardest that Ben and I have ever laughed while writing something. We were in our old house in Hollywood, in the basement of this house writing this thing and we were literally in tears because this monologue kept building on itself. We wrote it it one night and kept performing it back and forth, and pissing ourselves laughing.

You know, I was unaware, as I think everyone was, that they had that capacity. Snowden is literally changing policy. These are conversations we have to have about our security, and civil liberties, and we have to decide what we are willing to accept, and he’s provided a huge service kickstarting that debate…”

If you haven’t yet heard, tomorrow one of those conversations about our security, civil liberties, and what we’re willing to accept – it’s called The Day We Fight Back.

Thedaywefightback.org screen shot

“Together we will push back against powers that seek to observe, collect, and analyze our every digital action. Together, we will make it clear that such behavior is not compatible with democratic governance. Together, if we persist, we will win this fight.”



In the U.S.: Thousands of websites will host banners urging people to call and email Congress. Ask legislators to oppose the FISA Improvements Act, support the USA Freedom Act, and enact protections for non-Americans.

Outside the U.S.: Visitors will be asked to urge appropriate targets to institute privacy protections.

Global events: Events are planned in cities worldwide, including in San Francisco, Los Angeles, Chicago, Copenhagen, Stockholm and more. Find an event near you.

Add the banner to your site now: Grab the banner code on thedaywefightback.org. They’ve built special plugins for WordPress and CloudFlare users and also have a special version of the banner that pushes people to call over email.

Will you join us? 

Guest Post: Can you trust a VPN to protect your privacy?

Privacy by policy vs. privacy by design: At SpiderOak we always preach privacy by design, we don’t *choose* to not see your data, we just *can’t*.

Sadly, a lot of online services cannot take on that philosophy, simply because of how the internet works right now. This is the case of VPN. VPNs are a great service, but depending on what you want or need, they might have some drawbacks, as we commented on our VPN, privacy and anonymity post.

If after understanding the contents of that post, you still want to use VPN, you will want to use one that is run by someone or some company that is trustworthy, because they will *choose* to protect your privacy. We believe IVPN is a really good example of how this kind of services should be run, so without further ado, we continue this post with a few words from Nick from IVPN.  – Tomas


This article was written by IVPN’s Nick Pearson. IVPN is a privacy-orientated VPN platform, an Electronic Frontier Foundation member, dedicated to protecting online privacy.

For many years commercial Virtual Private Network companies have promised customers freedom from online surveillance and data retention practices. But with the government seemingly waging war on online privacy, is it really possible for a VPN company to protect its users – and how do you know which VPNs actually take online privacy seriously?

 How secure is a VPN?

 Firstly, any individual who has a critical need to avoid surveillance, such as political dissidents or anyone whose life may be at risk, should not rely on a single privacy tool to protect them – whether it’s a VPN, a free tool like The Onion Router, or I2P. In such scenarios, advanced set-ups, involving compartmentalization and isolation via a combination of virtual machines, VPNs and Tor, would be required (you can check out IVPN’s guide to advanced privacy solutions here). It’s also worth noting that even highly sophisticated set-ups probably won’t protect you from targeted surveillance by global-scale intelligence agencies, which can marshal a level of resources and expertise far beyond any individual or company.

 However, generally speaking, most potential VPN customers simply want to avoid data retention at the ISP level and circumvent internet censorship. In this case a VPN service would be sufficient. But only if the company running the VPN actually takes privacy seriously in the first place.

 Privacy policies

 For instance, most VPN companies shield users from data retention by allowing them to circumvent their ISPs ability to log their IP address and connections to other websites. By using a VPN your ISP can only see that your connected to the VPN’s servers and not the website that you’re browsing. But for this system to work, the user has to trust the VPN company not to log IP addresses and connections itself.

 The sad fact is many VPN companies – and indeed some of the most popular VPNs on the market – do in fact log and store customers’ data. Some VPNs will even retain this data longer than many ISPs. Perhaps even worse is that some VPNs are not upfront about their data retention practices and do not state in their privacy policies exactly what data they store and for how long (some VPNs don’t even have privacy policies).

 A VPN company should wipe its data logs regularly, ideally within hours of them being created, so that any requests for the data cannot be met. However, even if a VPN doesn’t store data, users’ privacy can still be compromised. Any company could be subpeoned by local authorities and forced into recording data on particular user. There are precedents for this, such as the Lulzsec fiasco, which saw a US-based VPN forced into logging data by the FBI. It’s therefore good to know what jurisdiction your VPN operates within, so you can get an idea of how local authorities behave toward them. This is a grey area, as there are no countries (that we’re aware of) that will protect a VPN’s right to not log data. All you can do is try to avoid those countries whose authorities have a track record in zealous online surveillance.

 What questions do you need to ask?

 So if you’re thinking of signing-up to a VPN service what questions should you ask in order to determine whether or not they take privacy seriously. Here’s a few suggestions.

 Do they have a privacy policy? This sounds like a no-brainer, but you’d be surprised to discover some VPNs don’t even have a privacy policy, let alone one that’s up to scratch. If they don’t bother telling you their approach to privacy, steer clear.

 How long do they retain logs? The vast majority of VPNs will log data for network troubleshooting purposes. However, there’s no reason to store data longer than a few days, unless the company is eager to comply with requests from authorities or from other third parties such as copyright holders. Ideally, a VPN should be wiping logs within hours. If the VPN doesn’t say how long it retains data then ask them directly. A good place to start is this list of VPNs that don’t log data.

 What country is the VPN registered in? Knowing what country the VPN is registered in will let you research the country’s laws pertaining to online privacy. As mentioned above, there are no countries that offer complete sanctuary for VPNs who don’t want to log data, but some are better than others.

 What other personal data will the company retain? It’s important to know whether a VPN can link your account to a real identity. Does the VPN require an address, or credit card information? Can you use a more anonymous form of payment such as Bitcoin?

 What will the VPN do if laws change? With governments around the world cracking down on online freedoms, it’s quite possible that VPNs could come under scrutiny. It’s therefore important that a VPN company notify its customers of any change in local laws, which may affect its ability to protect user privacy.