4 ms·
While Seafile seems to work, the developers have been kinda sloppy both with licensing[1] and security[2]. The answers on both issues really make me question th
by embik 10y ago
While Seafile seems to work, the developers have been kinda sloppy both with licensing[1] and security[2]. The answers on both issues really make me question their integrity and ability to deliver a secure piece of software.
[1] https://github.com/haiwen/seafile/issues/666 https://github.com/haiwen/seafile/issues/666
[2] https://github.com/haiwen/seafile/issues/350 https://github.com/haiwen/seafile/issues/350
- gstuartj 10y agoOwnCloud actually has security issues similar to what you cited in the second link. Their security track record isn't spectacular either. https://blog.hboeck.de/archives/880-Pwncloud-bad-crypto-in-the-Owncloud-encryption-module.html https://blog.hboeck.de/archives/880-Pwncloud-bad-crypto-in-t...
- LukasReschke 10y agoI'd like to point you to https://statuscode.ch/2015/09/ownCloud-security-development-over-the-years/ https://statuscode.ch/2015/09/ownCloud-security-development-... and make you aware of https://seacloud.cc/group/3/wiki/security-records.md https://seacloud.cc/group/3/wiki/security-records.md and you should probably consider who reported the last critical vulnerability. Only because a project is serious about actually publishing vulnerability data does not make it necessarily more insecure (or secure).
- gstuartj 10y agoI agree. Just pointing out that the specific problem the above poster mentioned as a reason to choose OwnCloud also is similarly true of OwnCloud. https://blog.hboeck.de/archives/880-Pwncloud-bad-crypto-in-the-Owncloud-encryption-module.html https://blog.hboeck.de/archives/880-Pwncloud-bad-crypto-in-t...
- LukasReschke 10y agoThe impact is a different one though. In that scenario pointed by Hanno somebody needs to have access to the storage which already requires some kind of previous gained access. What could be done by an attacker then is to infect EXE files or so. In the case of Seafile one could simply change passwords of any user etc. But yes, crypto is hard and I agree that the way we did it at ownCloud is far away from the best way. :-)
- mkesper 10y agoI hope there can be an updateable packet in Debian again with this fork.