The problem is just that they haven't been! According to their TOS until just over a month they were HIPAA compliant as a secure online service abiding by the set rules.
Why would you assume that things that you store online is 'public'? Do you assume the same with bank information? or do you just not use online banking or bill paying?
You can always check out SpiderOak (https://spideroak.com) or Wuala,com. Client side encryption key creation, zero-knowledge, cross platform, sync and mobile clients.
Not if issued by Bank of America, crooked liars. Worst institution on earth. Just a bunch of heartless greedy bastards that if society had some balls should be in the stockades.
Bank of America is a symbol of everything that is wrong with corporate America. The world would be so much of a better place if they could just have disappeared in the financial crisis.
This is very much the sad part. Groupon (with a possible IPO valuation of $25 BILLION+) does not even have to 'fail' to drag the entire IPO/.com/Tech market with them. They just have to 'not be a massive success' and shit will hit fans!
I would prob argue that Groupon as a company is neither. However, their fund-raising model is clearly a pyramid scheme where early and mid investors are 'banking' not on the business model itself paying out but ONLY on the fact that they will be able to dump their share as part of an IPO.
Who here really thinks any of the 1 billion investors in the last round are looking at 'holding on through thick and thin'?
If you have a business model that relies on throttling data capacity until your service becomes useless. Then you have a shitty business model. Period!
I don't consider it 'natural that any provider of supposedly secure storage would hold the account owners encryption key. It's not hard (as proven by SpiderOak and Wuala) to implement client side encryption. It does however make it impossible (hard) to cross-account deduplicate which makes storage costs higher for the operator.
I think the issue here is that dropbox tried to position themselves as 'as secure as everyone else' while actually holding the encryption keys and deduplicating across accounts, something that is not true for their competition.
The article alleges that SpiderOak (https://spideroak.com) does not deduct data. This is not however correct. SpiderOak deduplicates data but on an per account level and not cross-account since security prohibits this.
MAYBE an energy company shouldn't use unlocked 3G cards to insecurely transmit data and allow anyone who gets their hands on a card to rack up $200k? Just saying.
For those interested in building cloud apps we at SpiderOak offer a 'Do it yourself' Storage API that is designed specifically towards backup, sync etc.