MEGA review: A deep dive into the cloud storage and file sharing service

MEGA offers secure cloud storage and file sharing. This review highlights its user-friendly interface, selective sync, mobile apps, and more.

May 31, 2024 - 17:34
May 31, 2024 - 17:35
MEGA review: A deep dive into the cloud storage and file sharing service
MEGA

Our Verdict

Our Verdict

MEGA is a cloud storage service that has gained popularity for its strong focus on privacy and security. One of its key features is end-to-end encryption, which means that only the user has access to their files. This is a significant advantage for users who prioritize data security. In terms of storage options, MEGA offers a range of plans to suit different needs. The free plan provides 15GB of storage, which is quite generous compared to some other cloud storage services. There are also several paid plans available, offering additional storage and features such as advanced sharing options and increased bandwidth.

like Pros

  • File versioning
  • Open source code
  • No data stored in the US
  • Free and premium options
  • Extensive storage options

dislike Cons

  • Not open-source
  • Complex free plan
  • No live chat or phone assistance
  • Limited collaboration capabilities
  • Absence of published third-party audits or evaluations
MEGA
4.5
star star star star star
Our ratings take into account a product's cost, features, ease of use, customer service and other category-specific attributes. All ratings are determined solely by our editorial team.

Starting price

$11.71/per month or $117.19/yearly

Free version

Yes

Online file sync

Yes

MEGA is often discussed in conversations about privacy-focused cloud storage services. This service, based in New Zealand, provides end-to-end (E2E) encryption that even MEGA cannot decrypt, a generous free account, sync clients for various devices, and more. E2E encryption is essential in today's world, where no one, not even allied nations, is immune to surveillance by powerful organizations like the NSA.

Is MEGA the right cloud storage service for you? This MEGA cloud storage review will examine its features in detail to help you decide.

MEGA feature summary

Here is a brief overview of the main features offered by MEGA. Please note that certain features are exclusive to PRO or Business account holders.

  • Compatible with Mac, Windows, and Linux desktops
  • Browser extensions for Android, iOS, Chrome, Firefox, and Opera
  • Utilizes AES-128 and TLS for end-to-end data encryption
  • Storage options range from 15GB to 16TB
  • Synchronization across all devices and browsers
  • Administrative reports and analysis tools
  • Support for two-factor authentication (2FA)
  • File versioning functionality

Company information

MEGA was founded in 2013 in New Zealand by Kim Dotcom. Although Mr. Dotcom cut all ties with MEGA in 2015, the company has continued to expand successfully. As of this review, the service boasts over 166 million registered users globally.

MEGA terms of service

I examined the latest MEGA Terms of Service (ToS), a comprehensive document effective as of 18 December 2020. The ToS stipulate that all aspects of the service are subject to New Zealand law, including any arbitration proceedings that may arise.

Key points from the ToS include:

  • The service is governed by New Zealand law and you must comply with the Harmful Digital Communications Act 2015 (NZ) or similar laws in other jurisdictions.
  • You are prohibited from storing, using, downloading, uploading, sharing, accessing, transmitting, or making available unsuitable, offensive, obscene, or discriminatory information.
  • You are responsible for the use of your account, even in the event of unauthorized access.
  • You must not infringe upon any copyright or proprietary rights.
  • MEGA considers all takedown notices to be valid and will act upon them accordingly, requiring you to contest the removal of your content.
  • Both you and MEGA are bound by the Privacy & Data Policy and Takedown Guidance Policy, which outline MEGA's right to disclose data as required by law or competent authorities.

While the ToS are generally reasonable, certain clauses raise concerns. It may be challenging to determine if the data you store could be deemed unsuitable or offensive under laws similar to the Harmful Digital Communications Act 2015 (NZ) worldwide. Additionally, the takedown policy assumes guilt of infringing others' rights based solely on allegations, similar to the United States DMCA. The Electronic Frontier Foundation (EFF) article linked discusses potential issues with these requirements.

It's important to note that MEGA must adhere to New Zealand law and implement these policies. Whether your use of the service could lead to issues is something you must assess for yourself.

MEGA privacy policy

I've also examined the MEGA Privacy Policy, which is another extensive document last updated on December 18, 2020. Essentially, the policy states that MEGA adheres to the EU's GDPR for all its users worldwide.

Key points from the Privacy Policy include:

  • User data is encrypted on their device, and MEGA cannot decrypt it.
  • Files are stored in secure facilities in countries that the European Commission has deemed to have an adequate level of protection under Article 45 of the GDPR, depending on the user's location. None of the files are stored in, or accessible from, the United States of America.
  • Chats conducted within MEGA are encrypted, although some metadata must remain unencrypted to enable the service to function.
  • MEGA collects unencrypted metadata related to user accounts, such as browser type, operating system, IP address, and similar information.
  • Website Usage Data is collected by MEGA and used for advertising, marketing purposes, and to improve their business.
  • MEGA can share user data with law enforcement, related or affiliated entities, payment processors, and resellers, but they will never sell user data.

The collection of IP addresses might be a concern for some users. If you use a reliable VPN service, your real IP address will remain hidden. Two highly recommended VPNs are NordVPN and ExpressVPN.

Security audits and other third-party assessments of MEGA

I couldn't find any details regarding third-party audits or certifications for MEGA. However, they initiated a Vulnerability Reward Program in 2013, offering up to €10,000 for each discovered bug.

MEGA also makes their client-side apps' source code available for public scrutiny (refer to Transparent Source Code later in this assessment). This provides some insight into the functionality of the code.

In summary, although there's no evidence to suggest that the service doesn't perform as promised, there's a lack of third-party confirmation regarding MEGA's functionality.

MEGA platforms

With a user base exceeding 160 million, one would anticipate that MEGA provides a comprehensive suite of sync apps. Indeed, MEGA users are equipped with:

  • Full-featured apps for iOS, Android, and Huawei devices
  • Browser extensions for Chrome, Firefox, and Edge
  • Desktop apps for Mac OS, Windows, and Linux

Hands-on testing for the MEGA review

Let's briefly examine MEGA in action.

Installing MEGA

The installation process for MEGA is straightforward. Visit their website and create an account, providing an email address, password, first and last name. The email address must be valid, as you'll need to respond to a confirmation message as part of the setup.

After logging in, download and install the desired apps for your device. Once installed, log in to the app to begin using it.

Configuring MEGA

Once MEGA is installed on your device, you'll need to specify which folders you want to sync. Click the Syncs button, then Add Sync to open the Add Synchronized Folder dialog. Choose the local folder on your device and the corresponding MEGA cloud folder, then click OK.

MEGA will start syncing files to the cloud and will keep everything in sync going forward. Repeat this process for each local folder you wish to sync.

Clicking on Settings in a MEGA client opens a window where you can view your account status and make additional adjustments, although you may not need to use this feature often.

Using MEGA

If you only need MEGA to back up your files to the cloud, your setup is complete.

For those who wish to work with the synced files and folders, you can easily do so using the web client. Navigate through your files and folders by selecting Cloud Drive in the left-hand menu. You can perform actions like uploading, downloading, and previewing certain types of files by right-clicking on them.

MEGA file sharing

Sharing files is becoming increasingly important in cloud storage applications. MEGA's web app allows you to generate a link for any file you wish to share. You can opt to include a security key with the link, which means that anyone wanting to view the file will need to provide the key. The key can either be appended to the link (allowing anyone with the link to access it) or sent separately to the recipient.

In the sidebar menu, you can access the Shared with me section. Previously, MEGA was criticized for only tracking incoming shares. However, the Shared with me section now displays Incoming Shares, Outgoing Shares, and Public Links (links that do not require a key). These file-sharing features are excellent for collaboration, as is MEGA's MEGAchat feature (discussed below). However, due to its end-to-end encryption, MEGA does not integrate with third-party productivity or email applications. This sets it apart from Tresorit, which integrates with Gmail and Outlook, offering a more seamless file-sharing experience.

Additional MEGA features

MEGA offers several additional features that go beyond the basic functionalities we've covered. Here are some of the most notable ones:

MEGAdrop

Included in business accounts, MEGAdrop allows you to create a folder where individuals outside your organization can securely upload files to your account, even if they don't have a MEGA account themselves.

MEGAcmd

MEGAcmd is a command-line interface available for Mac, Windows, and Linux. It enables you to:

  • Set up automatic backups
  • Interact with WebDAV clients
  • Configure FTP access to MEGA files
  • And more, all through the command line.

MEGAbird

MEGAbird is a tool that integrates with the Thunderbird email client, allowing you to send large files through the MEGA network directly from Thunderbird.

MEGAchat

MEGAchat is an integrated chat system within the MEGA service. It uses user-controlled end-to-end encryption, ensuring that only participants in the chat can decrypt the messages. MEGAchat supports secure text, voice, and video calls with individual contacts or group text chats.

Transparent source code

MEGA provides access to much of its source code, allowing users to review it freely, which is a positive aspect. However, they only offer access to the client-side code, not the server-side code. Additionally, although the source code is viewable, it is licensed under custom licenses and does not meet the criteria for being considered open-source. A more detailed discussion on this matter can be found here.

To what extent is MEGA secure and private?

With easy access to substantial amounts of cloud storage, you're likely to store many important files in the MEGA cloud. However, hackers are increasingly adept at targeting even the most robust systems, as demonstrated by the recent hack of Electronic Arts. Given this scenario, let's examine how secure and private MEGA truly is.

MEGA security

MEGA employs end-to-end encryption for your data, utilizing keys known only to you. They use AES-128 encryption to safeguard data at rest and add an extra layer of TLS encryption when data is in transit. This means your data is secure.

You might be concerned that MEGA uses AES-128 instead of the stronger AES-256 for encryption. However, the reality is that while AES-256 is technically more robust, even the fastest computers available today would require many centuries to crack AES-128.

MEGA privacy

MEGA complies with the European Union's GDPR (General Data Protection Regulation) policies, which offer robust privacy protections. It's noteworthy that they extend GDPR protections to all their customers worldwide.

Another privacy measure is that MEGA explicitly avoids storing any user data in the United States. Given that the U.S. is home to some of the most powerful intelligence agencies globally, avoiding data storage there is a prudent move for privacy-conscious individuals.

While there are aspects of MEGA's Terms of Service (ToS) and Privacy Policy that are less than ideal, it's crucial to remember that the data you store in MEGA is unreadable to anyone except you or those with whom you share your encryption keys.

Since 2015, MEGA has published a yearly Transparency Report. These reports detail the number of requests for user data, files taken down, and users suspended for violating MEGA's ToS, among other issues.

The latest report reveals that MEGA takes down hundreds of thousands of files each year in response to takedown requests, though this affects only a tiny fraction of the 63+ billion files on the platform.

MEGA also receives over 1,000 requests for user information from law enforcement and civil complainants. Some of these requests are fulfilled using an automated tool that provides subscriber information directly to New Zealand police in specific cases.

While MEGA cannot provide the actual content of your files (as they cannot decrypt them), related metadata can still reveal information you might wish to keep private.

MEGA pricing

MEGA offers a range of accounts, from the free Individual account to four PRO accounts and a Business account. These accounts differ somewhat from other cloud storage services in that they limit the amount of data you can transfer over a given time period. The transfer limit, often referred to as bandwidth, applies for a specified time period. For example, a PRO LITE account offers 1TB of bandwidth per month, which is available immediately.

There are advantages and disadvantages to this approach. On the positive side, you have control over your usage. If you need to use all the bandwidth at once, you can do so without waiting for the next day. However, there is a risk of using up all your transfer quota early in the period, which could prevent you from accessing your files until the next month.

With these factors in mind, let's examine the MEGA accounts in more detail:

Individual account

The Individual account is a free plan that provides 50 GB of storage.

MEGA free storage?

In 2018, MEGA discontinued the 50GB free storage offer for new users. Presently, new users receive 15GB of permanent free storage, along with an additional 35GB bonus for signing up, which expires after 30 days.

Individual account holders need to complete various actions in the achievements program (such as installing the MEGA client or inviting friends to join) to earn additional storage. This additional storage also comes with an extra transfer quota. However, none of the additional storage or transfer is permanent. Once the additional storage expires, users are encouraged to complete more achievements or upgrade to a PRO account.

It's advisable to consider the Individual plan as offering 15GB of free storage unless you plan to consistently earn additional storage and transfer. While 15GB of free storage is respectable, the initial marketing of 50GB may seem misleading.

PRO accounts

MEGA offers 4 PRO accounts tailored for individuals, each with its own monthly or yearly storage limit and transfer quota. To acquire a PRO account, you must first create a free account and then choose to upgrade. This approach enables you to pay only for the storage capacity you require. However, as illustrated in the image below, there are considerable incentives to subscribe to the larger account tiers.

Each tier increase results in at least a doubling of both storage capacity and transfer quota.

Business account

MEGA provides a single Business account option that mandates a minimum of three users, billed at 10€ per user per month. This Business account offers more than just end-to-end encrypted storage; it includes features like voice and video conferencing, secure team messaging, file versioning, and user management capabilities. Additionally, users receive MEGAdrop functionality and mobile access on phones and tablets.

The MEGA Business account offers unlimited storage and transfer, which is a significant benefit. However, there is a caveat: the account must be used exclusively for genuine business purposes.

Curious about what constitutes "genuine business purposes" and who makes this determination?

Section 57 of the MEGA Terms of Service addresses this issue, with paragraph 57.5 providing specific details. It states that "Each user’s use of the business service must be fair, reasonable and not excessive, as reasonably determined by us…" with 'us' referring to MEGA. If you are considering a Business account, it's advisable to carefully review this section of the Terms of Service to ensure that your usage aligns with the criteria of being fair, reasonable, and not excessive.

In conclusion, MEGA has established itself as a leading privacy-focused cloud storage service. Your data is fully protected both in transit and at rest, thanks to end-to-end encryption that you manage. Additionally, you can share documents in encrypted form, ensuring that only those with whom you share the key can access them.

MEGA caters to a wide range of users, offering accounts for individuals seeking ample free storage, as well as businesses and teams. They have addressed previous shortcomings, such as the absence of two-factor authentication (2FA) and file versioning, further enhancing the service's appeal.