6 ms·
There is seafile ( https://www.seafile.com/en/home/ https://www.seafile.com/en/home/ ) which provides client side encryption. Easy to install and to upgrade (e
by JohnIcare 11y ago
There is seafile ( https://www.seafile.com/en/home/ https://www.seafile.com/en/home/ ) which provides client side encryption.
Easy to install and to upgrade (except a small glitch in the last upgrade).
For the community version, the source code is here : https://github.com/haiwen/seafile https://github.com/haiwen/seafile (see others haiwen projects).
The Android client could be improved, but it does the job.
- dchest 11y agoThis issue in Seafile was lovely: https://github.com/haiwen/ccnet/issues/35 https://github.com/haiwen/ccnet/issues/35 /* truly random sequece read from /dev/urandom. */ static unsigned char salt[8] = { 0xdb, 0x91, 0x45, 0xc3, 0x06, 0xc7, 0xcc, 0x26 }; https://github.com/haiwen/seafile/issues/587 https://github.com/haiwen/seafile/issues/587 Enough to understand if people writing this software know how to apply cryptography. This was 2 years ago, so I hope they improved.
- Artemis2 11y agohttps://xkcd.com/221/ https://xkcd.com/221/
- krylon 11y agoThanks for saving me from having to look that one up. Incredible that people will actually do this in production code. I don't understand a lot about cryptography, and even I know this not a good idea.
- dspillett 11y agoAlso, though less exactly relevant: http://dilbert.com/strip/2001-10-25 http://dilbert.com/strip/2001-10-25
- Semaphor 11y agoWhat seems truly scary is how little the developer seemed to care about those security bugs (following related issues, you also find an exploit, SQL injection and so on) and being dismissive of the guy who found them.
- embik 11y agohttps://github.com/haiwen/seafile/issues/587#issuecomment-40298104 https://github.com/haiwen/seafile/issues/587#issuecomment-40... > We don't roll our own crypto. > There are two parts of the code base in which "we roll our own crypto": the transfer protocl and encrypted library. That's just ridiculous.
- JohnIcare 11y agoFor information : since that github comment, now the protocol relies only on HTTPS. About metadata : https://seacloud.cc/group/3/wiki/seafile-roadmap.md https://seacloud.cc/group/3/wiki/seafile-roadmap.md there is one line saying "Ability to encrypt all data by server key. Key has to be generated by administrator" but it's not on the changelog page ( https://seacloud.cc/group/3/wiki/Server%20ChangeLog.md https://seacloud.cc/group/3/wiki/Server%20ChangeLog.md )
- Kunix 11y agoI would strongly recommend against using Seafile. Seafile stores a lot of metadata in clear text (including filenames): https://github.com/haiwen/seafile/issues/350 https://github.com/haiwen/seafile/issues/350 The developers know about it, the issue is 3 years old, this huge limitation is still not reflected on their documentation. An attacker who obtains a copy of the encrypted library without the key can: - read the complete list of directory and file names. - know the size of every file - know which files share some of the same information - see the history of who changed each file, when, and what byte ranges were altered
- xjqkilling 11y agoThis was 2 years ago. The situation is much better now. You can find how Seafile handles user passwords at http://manual.seafile.com/security/security_features.html http://manual.seafile.com/security/security_features.html