4 ms·
Not sure why you were downvoted, because I think you have a very good point. I often see us, as web developers, being blind to obvious, simple, local solutions.
by vog 9y ago
Not sure why you were downvoted, because I think you have a very good point. I often see us, as web developers, being blind to obvious, simple, local solutions. Perhaps this is because in many areas going from native to web is a win. Or, because too many web developers are exposed to business models around developing web applications mostly as a vehicle to fetch user data. (Fortunately, this is not true for intranet web applications which is a niche where I'm quite happy to work in.)
- jhunter1016 9y agoThere's nothing wrong with local applications. What Graphite is trying to solve for is the convenience of access across multiple devices without losing the privacy of what you'd expect from a local app. Happy to talk more about this in detail!
- icc97 9y agohow does this differ from local documents combined with dropbox?
- jhunter1016 9y agoGood question. The primary difference is that your file data is encrypted client-side before it ever reaches the storage provider of your choice. And that data can only be decrypted client-side in the app. You can, of course, PGP (as one example) encrypt your files yourself and store them on a local Dropbox folder that syncs. But, Graphite is encrypted by default without any additional work on the user's end. The other main difference is that you can share your files with anyone that has a Blockstack ID regardless of what storage method they use. You might use Dropbox while another user uses Azure, and neither user would know the difference, and the app will work seamlessly.
- icc97 9y agoYou can use Boxcryptor [0] on top of Dropbox to encrypt everything client side. That's much simpler than PGP. Yes I agree on the collaboration. I can see how this is more of a security/privacy minded replacement for Google Docs rather than a Word/Excel replacement. [0]: https://www.boxcryptor.com/en/ https://www.boxcryptor.com/en/
- guy98238710 9y agoEven simpler solution is to use encrypted backup/sync like SpiderOak or Tresorit. The point of Blockstack as I see it is that it decouples software from storage providers, which will hopefully result in large cheap encrypted storage combined with secure opensource software.
- chrisper 9y agoYou can also use free rclone[0], where you can mount all kinds of storage targets and encrypt your files. [0]: http://rclone.org http://rclone.org
- hobofan 9y ago> Boxcryptor Closed source + no audit is not exactly what you'd want to see from a piece of security software.
- ataturk 9y agoAlso legal precedent--cloud is not 4th Amendment friendly in the US. Our laws aren't keeping up as usual.
- candiodari 9y agoIt's not just that. The web is fundamentally incompatible with security against the server. ONLY local solutions can be secure against the author of the code being untrustworthy (ie. the security of the web fundamentally depends on MS, Google, Mozilla, IETF, etc. being trustworthy. Without that condition satisfied, even perfect code can be compromised). Let's say some webapp is actually really secure (when you first run it and generate the data, they're not cheating, and really upholding security), the docs are on your hard drive, you control the data storage, and so on and so forth. You might think, I made my docs using a secure program. They should be safe, right ? Okay ... Let's say the organisation behind it "goes bad", and now you want to access your docs. What happens ? You browse to their server. Your browser downloads the code to read the docs then and there from their servers. Nothing prevents the incredibly easy security problem: You browse to their server. Your browser downloads the code to read the docs and the code to fully break your security. (maybe the NSA /justice system compells them [1]) As long as both of these conditions is satisfied, there can be no security from the author of the code: 1) code gets changed without guarantees for it's security properties/thorough inspection 2) bidirectional connection for the code As long as both of these conditions are satisfied, you CANNOT be secure (meaning you don't have to trust anyone). Impossible. Mathematically impossible. Since the web fundamentally depends on both these properties, there can never be true security on the web. Call it candio's law. With local installs (e.g. Libre, Open or MS Office) you can secure everything and still have updates and fresh software. How ? Easy: have one-way data transmission from the internet to your machine. Download the programs onto a read-only drive (for the truly paranoid: write to DVDs or something that is fundamentally incapable of rewrites). Then use those read-only media to upgrade. That's enough to get OpenOffice running. And no matter how compromised OpenOffice is, the Apache project cannot access your data, nor can they do anything else, if you cover your bases. For instance, they cannot delete your data. They cannot prevent you from accessing your data. They have no power over you. And of course that will never work for Office 365/GoogleDocs or any kind of web replacement. Under basic security measures those products simply ... cannot work. [1] People think that it's the NSA going after their data. I'm sure that happens, but what is (by far) the most common reason a judge orders your mail copied to someone else ? Divorce (and related, e.g. alimony disputes). Second most common reason ? Commercial relationship gone sour. THAT's what you should be afraid of : all your mail sent to your competitors because you got into a legal fight with one of your suppliers. In practice I'm pretty sure more emails become exposed due to allegations of animal abuse than the NSA ever gets.