6 ms·
Show HN: CryptSend.io – Share encrypted files with randomly generated links
- trothamel 8y agoIs there any advantage to this over https://send.firefox.com/ https://send.firefox.com/ ?
- luizfzs 8y agoThe first thing that come to mind is that you can self-host cryptsend, while it doesnt seem to be possible to self-host send.firefox.com
- rhblake 8y agoYou can indeed self-host Firefox Send: https://github.com/mozilla/send https://github.com/mozilla/send
- jvehent 8y agoOr use the docker container directly: $ docker pull mozilla/send https://github.com/mozilla/send/blob/master/docs/docker.md https://github.com/mozilla/send/blob/master/docs/docker.md
- severine 8y agoThanks. Do you know of other self-hosted Mozilla products with ready-made containers?
- m-p-3 8y agoThanks for sharing! Looks like I'll use one of my VPS for that.
- cmurf 8y agoIt says "Big Files" but I don't see an explicit size. Whereas send.firefox.com is 1GiB. Self hosted I imagine you're only limited by filesystem max file size. One thing I like about send.firefox.com is it's a one time download, and then the URL is denied to have ever existed. CryptSend sounds like you could share the URL with multiple destinations; multiple downloads.
- justusthane 8y agoFirefox Send doesn't have an explicit limit either: > For the most reliable operation, it’s best to keep your file under 1GB
- CiTyBear 8y agoHi. Thank you for your work, this will be useful. However, the `Get folder link` does not work. Is it deactivated for now ?
- ech085 8y agoHmm, it's working for me on Chrome. What browser are you using? Do you see any javascript errors in your dev tools console (provided you know what that is)?
- madmaniak 8y agoIf the key is attached in link it also should be passed secure way, which is not usually.
- StefanKarpinski 8y agoThe option to also require a pass phrase for decryption would help.
- prophesi 8y agoYeah, the best solution I've found was Sharelock[0], but I couldn't for the life of me self-host the app without weird errors cropping up. It's also not free if you want more than one social sign-in via Auth0. [0]: https://sharelock.io/about https://sharelock.io/about
- kodablah 8y agoTempted to make a version of this myself because it's simple. Single file executable, with statically linked Tor, that starts a v3 onion service (with or without client auth), hosts web server with file at URL, gives onion address URL (and client auth if any, could include the as part of URL or URL fragment or whatever depending upon approach desired). Client can use exe or Tor Browser to download it. Could add any features you want such as killing the server after first download, deadlines, etc. Pro: doesn't upload to server and preserves anonymity. Con: slower than non-anonymous. Here's a simple code example of a v2 onion file server using external Tor process w/ no auth: https://github.com/cretz/bine#example https://github.com/cretz/bine#example. This is essentially what onionshare does: https://github.com/micahflee/onionshare https://github.com/micahflee/onionshare.
- gprasanth 8y agoI've recently analysed pricing of various storage providers when thinking of building a side project, and I was surprised at how costly the services were. S3, Drive, Dropbox, Spaces, B2, Box, several Object Storage solutions. Some cases storage was cheap, but the transfer was costly. Everything seemed costly for the simple use case of providing an end user 10GB monthly upload + ~50GB bandwidth at low cost. A vps with additional storage seemed to be the ~better~ most feasible solution to me. This sounds like a terrific thing to host on a vps.
- codetrotter 8y ago> This sounds like a terrific thing to host on a vps. Just make sure your provider has backup and redundancy in place for the data storage. Imagine waking up to total loss of data for all of your customers. Ouch!
- JepZ 8y agoRecently I have become a fan of the Hetzner Cloud: https://www.hetzner.com/cloud?country=us https://www.hetzner.com/cloud?country=us I don't know how competitive their prices are, but I like their easy to use interface which is complemented by and also easy to use API. Adding a 7-day automatic backup history is just a matter of about two clicks, and the additional costs seem reasonable to me.
- gregmac 8y agoNightly backups still mean you can lose up to ~24 hours of data. This is in stark contrast to, for example, AWS S3. From the FAQ [0]: > Amazon S3 [is] designed to provide 99.999999999% durability of objects over a given year. This durability level corresponds to an average annual expected loss of 0.000000001% of objects. For example, if you store 10,000,000 objects with Amazon S3, you can on average expect to incur a loss of a single object once every 10,000 years. > Amazon S3 ... storage classes redundantly store your objects on multiple devices across a minimum of three Availability Zones (AZs) in an Amazon S3 Region before returning SUCCESS. In AWS parlance, an AZ is a physical data center, and they're built far enough apart so a fire, flood or tornado will not affect all of them. There's a reason S3 (and similar) cost so much more than "hard drive attached to a server" storage. If you don't need the durability than of course it is overpriced -- but on the other hand, if you try to provide that level of durability yourself you'll quickly see it's a bargain. [0] https://aws.amazon.com/s3/faqs/#Durability_.26_Data_Protection https://aws.amazon.com/s3/faqs/#Durability_.26_Data_Protecti...
- threesquared 8y agoI made something like this a while ago. I think the name has a better ring to it though.. https://sendsh.it/ https://sendsh.it/
- uncled1023 8y agoSo one thing, it mentions that it is JS dependence free. How are you encrypting the files client side then? If you are encrypting the files server side, then that is NOT E2E encryption.
- jesseb 8y agoThere are JavaScript files in the GitHub repository, so I'm going to assume they mean third-party dependencies, but some more clarification would be nice. There is a file called cipher.js with encrypt and decrypt functions https://github.com/countable-web/cryptsend/blob/develop/public/js/cipher.js https://github.com/countable-web/cryptsend/blob/develop/publ...
- uncled1023 8y agoYea, and I just noticed it downloading a bunch when visiting the page. So it's probably safe to assume they mean 3rd Party.
- ech085 8y agoConfirmed. The intent is anyone can audit our whole codebase in one GitHub repo for vulnerabilities and not scripts spread across many CDNS and projects which may change over time.
- JepZ 8y agoI wonder what JS dependencies FTP has...
- ech085 8y agoGood catch, thanks! We'll fix that.
- lifeformed 8y agoThe first thing I thought of when I saw the url is that it's some kind of cryptocurrency transfer service. It's pretty crazy how much cryptocurrency has hijacked the word "crypto".
- ohashi 8y agoAmusing to see something that looks almost the same as a project I worked on with a couple friends 5 years ago. https://securesha.re/ https://securesha.re/ It's open source too.
- sbarker 8y agoWhy are all the "m" gray?
- lioeters 8y agoLooks to be caused by the font they're using, "Comfortaa". With font weight 600, the "m" is lighter than other letters.
- whitef0x 8y agoHello HN! Cryptsend was created as a result of my company having to share large amounts of medical data with our clients. We couldn't find an easy and secure solution, so we sat down and created cryptsend. Our codebase is currently in alpha stages so any audits/improvements/security vulns you find would be really appreciated!
- devinl 8y agoSeems like a bit of an oversight that they are including third party tracking scripts like googletagmanager.com in the same context as the javascript doing encryption. If you need user tracking, at least put the tracking scripts in an iframe sandbox or something that can't accidentally grab the keys from the URL fragment and send them off to google. Also they do call out that URL fragments get stored in browser history which is a big risk, but they should also mention that many browsers automatically "sync" history across devices (so keys will get sent to a cloud if you aren't using incognito/private browsing).