[{"data":1,"prerenderedAt":172},["ShallowReactive",2],{"vs-mega":3},{"id":4,"title":5,"body":6,"competitor":115,"date":118,"description":119,"draft":120,"extension":121,"features":122,"meta":166,"navigation":125,"path":167,"seo":168,"stem":169,"verdict":170,"__hash__":171},"vs\u002Fvs\u002Fmega.md","Hoodik vs MEGA: An Encrypted MEGA Alternative You Can Audit",{"type":7,"value":8,"toc":107},"minimark",[9,13,16,21,24,27,30,33,36,40,43,46,49,52,55,67,71,74,77,80,83,86,90,93,96],[10,11,12],"p",{},"MEGA gives you 20 GB free and 2 TB for around €9.99 a month, all end-to-end encrypted by default. On price and free tier it beats everything else in this comparison, Hoodik included, and by a wide margin. If storage economics are the deciding factor, stop reading and use MEGA.",[10,14,15],{},"The rest of this page is about the one thing that should make you hesitate.",[17,18,20],"h2",{"id":19},"the-2022-attacks","The 2022 Attacks",[10,22,23],{},"In 2022, Matilda Backendal, Miro Haller, and Kenneth Paterson at ETH Zurich published \"MEGA: Malleable Encryption Goes Awry,\" a set of practical attacks against MEGA's cryptographic design. The headline result: a malicious MEGA server could recover a user's RSA private key after roughly 512 logins, by using the client as an oracle. With that key, it could then decrypt file keys and read files.",[10,25,26],{},"The paper also described plaintext recovery and a framing attack that let a malicious server plant files in a user's account that appear to have been uploaded by the user. A separate team followed with a related Bleichenbacher-style attack on the same RSA handling.",[10,28,29],{},"The important detail is the threat model. These are not attacks by an outsider who breached MEGA. They are attacks available to MEGA's own servers, or to anyone who controls them. That is precisely the adversary end-to-end encryption is supposed to make irrelevant. The property MEGA sells is the property the attacks broke.",[10,31,32],{},"MEGA responded quickly and shipped fixes. The researchers' assessment was that the changes were targeted patches rather than the architectural rework they had recommended. MEGA has continued to make improvements since.",[10,34,35],{},"Two things are worth saying plainly. First, there is no evidence any of this was exploited against real users. Second, these bugs were findable because MEGA publishes its client source, which is more transparency than pCloud, Icedrive, or Sync.com's desktop apps offer. Publishing the code is what got them fixed.",[17,37,39],{"id":38},"what-hoodik-does-differently","What Hoodik Does Differently",[10,41,42],{},"Hoodik's cryptography was designed knowing how the earlier generation went wrong, which is an advantage of arriving later rather than of being smarter.",[10,44,45],{},"Key wrapping is a hybrid of X25519 and ML-KEM-768, the post-quantum KEM standardized by NIST, rather than raw RSA. Hybrid construction means an attacker has to break both the classical and post-quantum halves. It also sidesteps the family of RSA padding and malleability problems the MEGA attacks lived in.",[10,47,48],{},"File encryption uses AEGIS-128L, an authenticated cipher, so ciphertext that has been tampered with fails to decrypt rather than producing attacker-influenced plaintext. Ascon-128a and ChaCha20-Poly1305 are also supported, and the cipher used for each file is recorded so old files keep decrypting after a default changes.",[10,50,51],{},"Authentication uses OPAQUE, an asymmetric password-authenticated key exchange. The server never receives your password or any value derived from it that could be attacked offline, which removes the login path as a place to build an oracle.",[10,53,54],{},"The server is source-available Rust. You can read what the server does with every request, which is the half of the system MEGA does not publish and the half the 2022 attacks were mounted from.",[10,56,57,58,62,63,66],{},"On the client side MEGA is ahead of us and it should be said plainly. MEGA publishes its full client source; Hoodik publishes the web client and the ",[59,60,61],"code",{},"cryptfns"," and ",[59,64,65],{},"transfer"," crates that do the actual encryption in every client, including the mobile apps through Rust FFI, but not the Flutter application built around them. So the encryption path is readable on both sides, and MEGA's app shells are readable where ours are not.",[17,68,70],{"id":69},"where-mega-wins","Where MEGA Wins",[10,72,73],{},"Price, clearly. Around €4.99\u002Fmonth for 400 GB and €9.99\u002Fmonth for 2 TB. A Hoodik Cloud instance is €19\u002Fmonth for 500 GB, because it provisions a dedicated instance with its own database and storage bucket rather than space on a shared system. Per gigabyte, MEGA is several times cheaper and there is no argument to make there.",[10,75,76],{},"The free tier. 20 GB at no cost with no card, against a 14-day Hoodik Cloud trial. Self-hosted Hoodik is free and unlimited, but that requires a machine.",[10,78,79],{},"Desktop sync, MEGAcmd, browser extensions, chat, and meetings. MEGA is a broad product with years of client development behind it, and Hoodik has no folder-sync daemon.",[10,81,82],{},"Maturity. MEGA has been running at large scale since 2013 and has handled far more traffic and far more edge cases than Hoodik has.",[10,84,85],{},"MEGA does meter transfer volume per plan, which self-hosted Hoodik does not, but for most usage that quota is generous.",[17,87,89],{"id":88},"who-should-use-which","Who Should Use Which",[10,91,92],{},"For a large media library where the encryption is a nice default rather than a requirement, MEGA is the rational choice on price alone. Nothing here changes that.",[10,94,95],{},"Hoodik is the answer when the encryption is the actual product. If you are choosing an encrypted service because you need the provider to be unable to read your files, then a documented, published break of exactly that property is the most relevant fact available about the candidates, and it should weigh heavily even after the patches.",[10,97,98,99,106],{},"Beyond the history, the practical differences are the post-quantum key wrap for anything with a long secrecy lifetime, a published server rather than a published client, and the ability to stop depending on a vendor. Run Hoodik on your own hardware for free, or on ",[100,101,105],"a",{"href":102,"rel":103},"https:\u002F\u002Fhoodik.cloud",[104],"nofollow","Hoodik Cloud"," at €9\u002Fmonth for 100 GB or €19\u002Fmonth for 500 GB, with the whole instance exportable to a server you control whenever you want it.",{"title":108,"searchDepth":109,"depth":109,"links":110},"",2,[111,112,113,114],{"id":19,"depth":109,"text":20},{"id":38,"depth":109,"text":39},{"id":69,"depth":109,"text":70},{"id":88,"depth":109,"text":89},{"name":116,"website":117},"MEGA","https:\u002F\u002Fmega.io","2026-07-29","MEGA is cheap per terabyte, but academics broke its encryption model in 2022. Hoodik is a MEGA alternative with auditable code and post-quantum key wrapping.",false,"md",[123,127,130,133,137,140,142,144,147,151,155,157,161],{"name":124,"hoodik":125,"competitor":125,"note":126},"E2E Encryption",true,"Both encrypt client-side by default. The difference is in the design and its track record, covered below.",{"name":128,"hoodik":125,"competitor":120,"note":129},"Encryption Model Never Broken","In 2022 researchers at ETH Zurich published practical attacks against MEGA including RSA private key recovery after 512 logins, plaintext recovery, and file framing. MEGA patched, and the researchers described the fixes as falling short of the rework they recommended.",{"name":131,"hoodik":125,"competitor":120,"note":132},"Post-Quantum Key Exchange","MEGA's key handling is RSA-2048 and AES-128. Hoodik wraps every file key with a hybrid of X25519 and ML-KEM-768, the post-quantum KEM standardized by NIST.",{"name":134,"hoodik":125,"competitor":135,"note":136},"Password Never Sent to Server","partial","Hoodik uses OPAQUE, so no password-derived value reaches the server. MEGA derives an authentication value from your password client-side and sends it.",{"name":138,"hoodik":135,"competitor":125,"note":139},"Client Source Available","MEGA publishes its full client source, which is how the 2022 attacks were found, and that is more than Hoodik offers. Hoodik's web client is public, as are the cryptfns and transfer crates that perform encryption in every client including the mobile apps. The Flutter app around them is not published.",{"name":141,"hoodik":125,"competitor":120},"Server Source Available",{"name":143,"hoodik":125,"competitor":120},"Self-Hosted Option",{"name":145,"hoodik":146,"competitor":125},"Managed Hosting","Hoodik Cloud, from €9\u002Fmo",{"name":148,"hoodik":149,"competitor":150},"Jurisdiction","Your choice","New Zealand (Five Eyes)",{"name":152,"hoodik":153,"competitor":125,"note":154},"Transfer Quotas","None","MEGA meters download and transfer volume per plan. A self-hosted Hoodik instance has no quota; Hoodik Cloud is limited by storage, not transfer.",{"name":156,"hoodik":120,"competitor":125},"Desktop Sync Client",{"name":158,"hoodik":159,"competitor":160},"Free Tier","Unlimited self-hosted","20 GB",{"name":162,"hoodik":163,"competitor":164,"note":165},"Pricing","Free self-hosted · Cloud from €9\u002Fmo","~€4.99\u002Fmo for 400 GB, ~€9.99\u002Fmo for 2 TB","Per gigabyte MEGA is several times cheaper than a dedicated Hoodik Cloud instance. Self-hosted Hoodik is free and capped only by your disk.",{},"\u002Fvs\u002Fmega",{"title":5,"description":119},"vs\u002Fmega","Pick MEGA for the cheapest large-scale encrypted storage and a 20 GB free tier. Pick Hoodik if a documented break of the encryption model, and the design decisions behind it, are disqualifying.","CAiVOo-NJqWeUy_wbJwg3lDP8sb-lxnQDN2FL2FZ8uY",1785479168335]