4 ms·
> Seafile has a much smaller attack surface (no PHP, MySQL not required, etc) ownCloud does run a successful Bug Bounty program and is paying for security bugs
by LukasReschke 11y ago
> Seafile has a much smaller attack surface (no PHP, MySQL not required, etc)
ownCloud does run a successful Bug Bounty program and is paying for security bugs: https://hackerone.com/owncloud https://hackerone.com/owncloud
Also I have published a blog post elaborating why CVEs are not everything when it comes to comparing the security of products: https://statuscode.ch/2015/09/ownCloud-security-development-over-the-years/ https://statuscode.ch/2015/09/ownCloud-security-development-...
Furthermore please take a look at https://seacloud.cc/group/3/wiki/security-records/ https://seacloud.cc/group/3/wiki/security-records/. Not using PHP doesn't make everything more secure magically, neither does using PHP make things more secure.
- tombrossman 11y agoThanks, good to know. The ownCloud Android client required duplicate copies of all the photos & videos (the original plus a copy in the ownCloud folder) which filled up storage on my phone too quickly. Once this is sorted I might try it again, even if only for the calendar and contacts. It has many features but I just don't need most of them.
- jancborchardt 11y agoThere is a pull request with a fix for the Android issue you describe: https://github.com/owncloud/android/pull/1168 https://github.com/owncloud/android/pull/1168 Would be very helpful if you can test it! :)