42 ms·
Firefox Send: Free encrypted file transfer service
- navaati 8y agoI must say I am disapointed. I thought this would be some cool realtime system to send from browser to browser, using WebRTC or something. Something that doesn't involve them paying for file servers, by the way. I believed in Mozilla ! But no, here we are and I just don't see the difference between this and Mega. EDIT: except for the auto-deletion trick that addresses the piracy problem. But still...
- gsich 8y agoBut that would require more brain and effort. Since many users are usually behind a NAT, some NAT-traversal is neccessary. Combined with a robust detection (for shitty networks) and fallback to "normal" servers ... you get the idea.
- cdoxsey 8y agohttps://file.pizza/ https://file.pizza/
- peterwwillis 8y agoThis is the tool I wanted to write! This is honestly the best solution I can imagine. It's FAXing for the 21st century
- Ultramanoid 8y agoIt's a fantastic service and I'm glad to see it leave the experiment stage and become official. Highly recommended.
- icemelt8 8y agoI wonder which cloud service they are using to store the files.
- Brosper 8y agoNice!
- Proven 8y agoIf they're committed to users' privacy how come there are so many FF "privacy tuning" scripts? Nice service but how is that better than posting encrypted files on one of established web drives (Dropbox, OneDrive, Google Drive, Keybase, etc?)? I can't imagine it's better and privacy-wise it's likely about the same. Important fact: google is probably best at monetizing this crap, so FF likely can't squeeze more dollars out of the same amount of data, which is why I think this service will ultimately not become popular.
- mFixman 8y agoI can't believe that there isn't a simple service to transfer data between my cellphone and my computer without going through the internet. iTunes is terribly bloated, MTP is a mess, and Bluetooth is slow and frustrating. Back in my hacker day I used to have an SSH server open on my cellphone and use it to transfer files back and forth with my computer. Why isn't there a mainstream service like that?
- dx87 8y agoKDE connect works without internet access. I haven't used it on Windows, but it works fine for me on Ubuntu.
- merpnderp 8y agoIn the Apple ecosystem, there's AirDrop which uses either Bluetooth or Wifi. You can quickly share files between any iOS and Mac devices very simply.
- matt-snider 8y agoWhat about https://syncthing.net/ https://syncthing.net/? EDIT: I know you said without going through the internet. Syncthing can be configured to only transfer over specific networks (e.g. home LAN/WI-FI)
- pard68 8y agoI use syncthing for all my personal file syncing. It is so useful and secure to boot!
- rcMgD2BwE72F 8y agoI've been using it for (almost) everything and it has always work perfectly: I keep my phone's picture in sync with my personal computers ("send only" so I can remove old photos when my SD card is getting full). I sync a "media" folder where I dump all the music and video I download with the youtube-dl CLI (a "yt" alias makes sure the files are stored in the right directory with some custom parameters). I sync my KeepassXC databases (work and personal), between my personal Linux laptop, my Android phone and my work MacbookPro. Databases can be merged in a single click if there's any conflict (happens very rarely). I love the Android secure autofill service and fingerprint quick unlock I use a "temp" folder to drag'n drop stuff between computers so I can file it properly on the right device. On Android, I prefer to use the Syncthing "sharing intent" to make any file/media available on my other devices in just a tap. I also have installed Syncthing on my Android TV, and occasionally drop HD movies that I download on my phone over P2P (I have a pretty fast connection, so it's easier for me to choose a move from my phone, while in commute, have it download in a few seconds, and either stream it to my TV via Chromecast or open it from the synced folder through Kodi) This really is a dream setup.
- TulliusCicero 8y agoNeat! How do they handle abuse though? Like, people using it to host, say, pirated TV shows? Maybe a max download limit that makes it impractical for that use case?
- Moter8 8y agoThe files are available up until they have been downloaded (from 1 to 100 times) or until a certain timeframe has elapsed (from 5 minutes to 7 days). See the screenshot at the article.
- warkdarrior 8y agoWe are working on a plugin for BitTorrent that will automatically re-upload a file to Firefox Send when the old link expires and then make the new link available in the torrent.
- fwip 8y agoThis is why we can't have nice things.
- richjdsmith 8y agoWhy? Why wreck a good thing so no one else can enjoy it? The torrent protocol is already there. Don't put that cost on the Mozilla Org.
- hbosch 8y agoI certainly hope that Mozilla can/will detect and punish this sort of abuse.
- mont 8y ago2.5GB file limit is a bit small for good quality TV shows (and especially movies).
- giarc 8y agoEven single episodes?
- fxfan 8y agoThere's also a command line interface somewhere
- emddudley 8y agoI've used this before to send sensitive documents to my attorney, who would have otherwise just wanted email attachments. It worked great.
- sigmonsays 8y agothis doesn't seem that impressive technology wise, but maybe i'll remember to use it.
- oblio 8y agoI wonder if they're running some malware scanners plus do they have to comply with DMCA takedowns? Based on what I see, the files are hosted on their servers, so they kind of have to, no?
- mehrdadn 8y agoThere is end-to-end encryption, so unless they have homomorphic virus scanners I don't see how they would do this...
- nvdk 8y agoAt maximum 200 downloads and an expiration of 7 days I don't think anyone will bother to be honest.
- TulliusCicero 8y agoHypothetically, you could wrap this storage solution in a service that automatically creates new underlying links as old ones exhaust their quota or expire.
- nvdk 8y agoI've been using send.firefox.com for months and so far the only downside was the 1 day expiration. Very glad you can now opt for 7 days.
- deleted 8y ago[deleted]
- buboard 8y agoThey could also offer a realtime webrtc solution like snapdrop.net . Although i m not sure that works, it didn't work between my phone and desktop.
- hlnas 8y agoHow "private" is it? Do you store metadata? i.e. if I upload a file and it expires, do you also delete any trace of me, including my IP address?
- mehrdadn 8y agohttps://send.firefox.com/legal https://send.firefox.com/legal > We receive IP addresses of downloaders and uploaders as part of our standard server logs. These are retained for 90 days, and for that period, may be connected to activity of a file’s download URL. Although we develop our services in ways that minimize identification, you should know that it may be possible to correlate the IP address of a Send user to the IP address of other Mozilla services with accounts; and if there is a match, this could identify the account email address.
- gurpreet- 8y agoWhy is it a necessity to store information for 90 days? Why not 10 or 30?
- mehrdadn 8y ago> Why is it a necessity to store information for 90 days? Why not 10 or 30? Is there something special about 10 or 30? (You wouldn't ask the same question about 10 or 30?)
- hlnas 8y ago10 or 30 seem shorter, no? I don't have anything to say about 10 or 30, but 90 seems too long in my opinion. I understand the need to keep logs to thwart abuse, but with longer lengths you're just helping law enforcement.
- mehrdadn 8y ago> 10 or 30 seem shorter, no? I don't have anything to say about 10 or 30, but 90 seems too long in my opinion. Sure they're shorter, but wherever they draw the line somebody like you is going to complain. Putting myself in their shoes I don't see any reason why you wouldn't complain about 30 days (even if you really wouldn't). > I understand the need to keep logs to thwart abuse, but with longer lengths you're just helping law enforcement. 90 days cannot be to thwart abuse because...? And helping law enforcement is inherently terrible because...?
- jasonjayr 8y agoIs the source available for this? A self-hosted version of this would be nice... (Update: Yep, just found it: https://github.com/mozilla/send https://github.com/mozilla/send, just before the comment below was posted :))
- jgruen 8y agoboop: https://github.com/mozilla/send https://github.com/mozilla/send
- xtracto 8y agoReminded me of zerobin / privatebin. We used this internally at a previous company to share passwords and sensitive files. Data is encrypted at client and a url with a key is generated. Can be used 'burn after reading or with some specific lifetime.
- lbeltrame 8y agoAs far as I can see, this requires S3 or a S3 compatible service. Kind of defeats the purpose of self hosting unless you can set one yourself (it may be, I didn't look). EDIT: Apparently there's a way to use filesystem instead of S3, it's just not well documented.
- alias_neo 8y agoMinio is your friend. (S3 compatible self-hosted, open-source object store). I recently implemented a text/snippet sharing tool that uses Minio instead of S3, because I like to self-host everything. https://minio.io/ https://minio.io/
- GordonS 8y agoI use this with Seafile to store data in Azure Blob storage - it was incredibly simple to setup and has been rock solid since. Highly recommended!
- techaddict009 8y agoLooks more like wetransfer.
- Oras 8y agoTrue, without the email. Actually, I like we transfer for sending emails and notifications when the user has downloaded the attachments.
- techaddict009 8y agoYou can use wetransfer without email too I think. my designer sends me that way. Probably signed up users can do so.
- hprotagonist 8y agoIt doesn't exactly meet the needs of "sending files to a non-technical person", but Magic Wormhole [0] has been truly great for flipping files around between me and anyone who is capable of being trusted to run `pip install --user pipe && pipe install magic-wormhole`. This is by no means everyone, but it's been very useful quite often. [0] https://magic-wormhole.readthedocs.io/en/latest/ https://magic-wormhole.readthedocs.io/en/latest/ has
- asutekku 8y agoI have no clue why you would suggest a tool that requires using a linux command line after telling firefox send doesn’t meet the needs of non-techical person.
- jacobush 8y agoNo, he's saying Magic Wormhole doesn't exactly need the needs of a non-technical person.
- detaro 8y ago"It" in the first sentence does refer to the solution they mention, not Firefox Send.
- hprotagonist 8y agomagic-wormhole works fine on windows and mac; nothing about sh-like shells is linux-specific.
- cherrypepsi 8y agoI remember elementaryOS had a GUI for this in its app store. Never got around to try it, Linux is not well known in the consumer world, let alone Elementary
- dTal 8y ago>pip install --user pipe && pipe install magic-wormhole What am I looking at here? On PyPI 'pipe' is listed as a "Module enablig a sh like infix syntax (using pipes)", and magic-wormhole's own docs just say to install with pip like anything else.
- kikikiki09i 8y agoHow to they pay for the storage costs?
- stunt 8y agoStorage is extremely cheap. Especially for a service like Send which doesn't hold any data for a long period of time. Elseways, It might be that they have bigger plans with it. This might be just a product to learn about market potentials. Mozilla's manifesto is all about the Internet and Internet privacy. File sharing is one of the areas where the internet is losing privacy.
- nukeop 8y agoI wish Mozilla focused on core Firefox functionalities instead of coming up with so many small side projects that don't target their typical audience. Since Chromium-based browsers are not an option, many of us are stuck with Firefox as the only remaining choice. But even Firefox has to be heavily customized before it's completely deGoogled and stops contacting various motherships. As a side note Nightly build for Ubuntu has been broken since version 61 and there's no sign of any effort to fix it.
- kvark 8y agoIs there anything specific you are missing in Firefox today? Or is it purely the fact that it's broken since version 61? Did you submit a bugzilla issue, or know the existing number? I'd be happy to check it out.
- nukeop 8y agoA million things, like missing functionalities from the new extensions api (meaning no Pentadactyl), no good way to manage keyboard shortcuts, having to disable many google integrations after installation, no way to disable "do not track" if using built-in tracker blocking, no sidebars a la Vivaldi, buggy rendering (e.g. transitions animating elements using css transforms), unexplained slowdowns, lack of proper tab isolation (one slow/crashed tab takes the whole browser with it), etc. I could rant all day.
- kvark 8y agoThank you! This is great input to us, it just needs a few more details to become actionable: bugs filed (for things that are not by design, of course, like the extension API), repro steps and detailed information provided. If I can reproduce it, I can file bugs myself, but I still need to get some clarifications on how to reproduce.
- kikikiki09i 8y agoHow do they pay for the storage costs? What's the upside for Mozilla?
- chrisseaton 8y ago> How do they pay for the storage costs? Using their revenue from search, like everything else they pay for. > What's the upside for Mozilla? "Our mission is to ensure the Internet is a global public resource, open and accessible to all. An Internet that truly puts people first, where individuals can shape their own experience and are empowered, safe and independent."
- passthejoe 8y agoUpside is that this is another reason to get a Mozilla account.
- sam_lowry_ 8y agoGoogle Search, Yahoo Search.
- AdmiralAsshat 8y agoI've used Firefox Send for several months while it was still a test pilot program. It's been very useful for quickly sending files to family. The fact that the link expires as soon as the other party downloads it means I don't have to worry about clean up.
- toomuchtodo 8y agoDoes the link expire after a successful transfer? Curious what happens if the transfer fails mid transfer and needs a retry.
- AdmiralAsshat 8y agoNo one I've tried it with has ever had it fail on them. But to answer your question, I uploaded a 100mb+ file to FireFox Send, copied the link, RDPd into another computer, kicked off the download, and then cancelled it midway through download. The link did expire after that. So I guess they don't have an easy way of telling whether the download is successful or not. Maybe Mozilla's engineers can figure something out if the issue is raised.
- toomuchtodo 8y agoI appreciate you took the time to run a test to answer my question. Thank you. Firefox might consider keying off the initial IP seen upon retrieval and extending the TTL of the object until the final byte has been retrieved.
- kbenson 8y agoI can see benefits to keying off the IP, but also to keying off some cookie that can expire shortly. One of the reasons I imagine a download might fail could be because of a spotty of problematic VPN or proxy, or attempting to get it from a location that can't handle it well if somewhat large (some random coffee shop wifi that's overused). There's probably enough complexity and possibility for abuse in allowing automated requests for files again (i.e. a button on the view page) or special logic for second attempts that the safest option is just to have the receiving party ask for the file again through whatever medium originally kicked off the request (an email, an IM, etc). Firefox could do any number of things to make it easier on the user, but I expect them to take my security and privacy very seriously and to error on the side of those ideas rather than usability, so hopefully if they come out with something it's not at odds with those goals.
- timvisee 8y agoI've been building a fully featured CLI tool for Firefox Send, supporting this new release. For anyone that is interested: https://github.com/timvisee/ffsend https://github.com/timvisee/ffsend
- kevinherron 8y agoThis is neat, thanks.
- drewg123 8y agoFWIW, I built and successfully ran it on FreeBSD-current. The only hiccup I ran into was that it puked building due to not having /usr/local/lib in its lib search path & not being able to find libxcb. I had to manually add -L/usr/local/lib to the cc args and manually link it. Not sure if that is a FreeBSD issue w/Rust, or something in your package. At any rate, the tool works! Thanks so much.
- timvisee 8y agoThanks for sharing your solution! Not sure what is causing it (maybe it's OpenSSL binding related), and am currently not really targeting FreeBSD yet. I wasn't fully ready with this tool for the Firefox Send release to be honest, would have loved to be able to provide better binaries and packages for more platforms, which are a work in progress. If you believe you can improve the README with your solution, be sure to submit a [PR](https://gitlab.com/timvisee/ffsend/ https://gitlab.com/timvisee/ffsend/). Happy to see it's working! :)
- diegorbaquero 8y agoI had the expectation that it would use WebRTC before opening the link, disappointed on that side. But really glad of the privacy minded offer. I appreciate Mozilla's work and effort towards a more private and encrypted internet!
- JohnFen 8y agoWebRTC and privacy don't exactly go together well.
- seveneightn9ne 8y agoHow is this using end-to-end encryption? It seems like the recipient just clicks a link to download. How can it have been encrypted for that person? end-to-end encryption normally means that there's no way for the intermediary to unencrypt the data but I can't see how that's possible in this case.
- weaksauce 8y agoClient side JavaScript that encrypts locally befor uploading and puts the encryption key in the url you share with someone that never gets sent to Mozilla. Also client side decryption on the person you shared the link with. It’s end to end.
- pault 8y agoWith the caveat about client side browser encryption in general, which I'm sure someone will pop in here and explain in detail. :)
- EwanToo 8y agoThe url effectively contains the decryption key, so the web server could be set to capture the urls and decrypt files. If you want, you can also set a passphrase on the file to share via another channel
- Vinnl 8y agoThat's why the key is in the hash part of the URL; the server can't access that (unless it also sends client Javascript that parses it and sends it back to the server, but that could be detected).
- SamuelAdams 8y agoWhat if I'm on a network I don't trust? Is the only option to set a passphrase? More importantly, the UI doesn't call this out explicitly, so uninformed users may think it's "secure enough" without a passphrase.
- tantalor 8y agoObligatory https://xkcd.com/949/ https://xkcd.com/949/
- kenrick95 8y agoThere's also a http://xkcd949.com/ http://xkcd949.com/
- ChrisArchitect 8y agowhat is the business case for this tho? Who pays for the bandwidth??
- usermac 8y agoYes, next to Apple's AirDrop, this is a welcome addition.
- voidmain0001 8y agoI'm onboard as a regular user of send.firefox.com. How does Mozilla have the money to offer this for free?
- snazz 8y agoMaybe they just don’t need too much storage since they expire quickly. This would be an interesting thing to graph, if they release the statistics.
- Vinnl 8y agoMozilla has quite a bit of money, most of it from their default search engine deals. I'd wager to guess that most of it goes to wages.
- danilocesar 8y agoNet income 2017: 89 million. Not that much for a company employing more than a thousand employees. But impressive for a corporation that is 100% owned by (and allegedly managed like) a non-profit org.
- Aissen 8y agoI wonder if they've fixed the issue where one can force reuse of a link by slowing down a download, and sharing the URL ? Hence turning it into a cheap file hosting service: https://news.ycombinator.com/item?id=15450524 https://news.ycombinator.com/item?id=15450524 I haven't been able to upload a file to try.
- laurent123456 8y agoHow does E2EE work if the recipient can download the file directly? I'd expect some key or password needs to be exchanged too?
- Vinnl 8y agoThey key is appended to the URL as a hash, which cannot be read by the server.
- romantomjak 8y agoI really don't understand why they didn't share a link to the repository in the article. For anyone who's interested - here it is: https://github.com/mozilla/send https://github.com/mozilla/send
- Cyphase 8y agoIt's because this blog is for mainstream audiences who don't know what GitHub is and might be scared of all that code-y stuff if they accidentally clicked on it.
- thekyle 8y agoI'm not so sure about that. I have a difficult time believing that anyone in the "mainstream audience" would take the time to read Mozilla's blog posts, or more generally the blog posts of any tech company.
- huhtenberg 8y agoVery clean and nice, but how is this financed? That is, who's paying for the server storage and the bandwidth?
- Vinnl 8y agoPresumably Mozilla, just like they do for the sync and Web Push servers.
- olig15 8y agoI think what the previous poster meant was 'why' are Mozilla paying for it?
- toomuchtodo 8y agoThe open web is more than just a browser. The cost is minimal when you have your own infra instead of AWS’ bandwidth gouging.
- thekyle 8y agoAnother user pointed out that Firefox Send is written to use an Amazon S3 compatible API to run. That could mean that Mozilla is using AWS for the service. https://github.com/mozilla/send#requirements https://github.com/mozilla/send#requirements
- toomuchtodo 8y agohttps://news.ycombinator.com/item?id=19370632 https://news.ycombinator.com/item?id=19370632
- Vinnl 8y agoAh. In that case, I seem to recall they performed user research among users of their browsers that uncovered that sending files to others was still a major pain point. It's also a way in to promote a Firefox account, and Firefox in general. Of course Mozilla's not in it for the money, so there's not a direct line from Send to more revenue. Firefox is their main tool to protect the open web, and Send is a way to get more people to use that. And of course, being able to send files encrypted is good for the web as well. Indirectly, it is primarily financed by the search engine deal in Firefox.
- intellent 8y agoIs there a simple way to get the direct URL of the file (e.g. to use in wget cli calls).
- ubercow13 8y agoThe file is decrypted in client-side JavaScript so presumably no
- deleted 8y ago[deleted]
- _bxg1 8y agoAh man, I literally came up with (and prototyped) this exact thing in 2013. Minus the end to end encryption. I dropped it mostly because I wasn't sure how to prevent illegal use and didn't want to be liable. Edit: mine was actually (partially) better because it assigned a short PIN instead of a full link, which meant you could just look at it and remember it for typing-in, instead of requiring a separate channel to "send" the link.
- tyingq 8y agoThe end to end encryption necessitates a hard to remember uri anyway, so I don't think you can have both "secure" and "memorable".
- _bxg1 8y agoYeah; ID length was definitely another challenge. Time-expiration helped, but. I was going with 6 digits as a middle ground but it wasn't super secure, even if an upload expired after a few minutes. And of course there was no way for the user to know for sure that I couldn't keep around a copy without the E2E.
- jdmichal 8y agoTheoretically, yes. But they could also derive keys from a shorter password value -- like password managers.
- TheShrug 8y agoA short PIN seems nice for personal use (maybe on a self-hosted service) but wouldn't a short PIN allow people to potentially guess random PINs and download files that they shouldn't have access to?
- _bxg1 8y agoThe hope was for the time limit to help improve those odds, but, yes. It was also not really intended for anything truly sensitive. The motivating case was when you're in physical proximity to the destination device, but don't have any account linkage between the two (not even messaging/email/social accounts that are connected). The original idea came from university computer labs: transferring homework between the lab computer and a personal one was a pain. I had to sign into dropbox in the browser (and 2FA), or attach it to an email, or carry around a flash drive (which wouldn't work on phones), or whatnot. Just to move the file three feet. A glanceable code with no sign-in bridged that gap. Other use-cases include people you don't know very well (and therefore don't have an email, phone number, etc.). We demonstrated the prototype to a crowd by uploading a file with the code visible on the projector, and suddenly everyone in the crowd had the file. That was pretty cool.
- woranl 8y agoI'm surprised that no one raised their concern about javascript encryption. Usually, some will point out that the user will have to trust the delivered client side code first. Has javascript encryption finally got mainstream now?
- NedIsakoff 8y agoHow are they going to deal with bad content? Child porn? Pirated content? Illegal stuff?
- mac01021 8y agoSince it's encrypted end to end, presumably they will be oblivious to all that stuff?
- NedIsakoff 8y agoSure, but doesn't help with the PR does it. If people start using it to send/dist the stuff, the news will mention it.
- tasty_freeze 8y agoThe same way backup services and email servers deal with encrypted data. They have no way of knowing.
- Secretmapper 8y agoThis is perfect! I'm currently taking a networking class where we generate trace reports, and I've just realised how tricky it is to send files without logging in (I'm just averse into doing that in a machine that's not mine). I can email my trace files, but I need to login, I can store in dropbox/drive, but again I'll have to login. I wish they added a QR code option as well. It would be perfect for quickly copying the link by snapping it with my phone so I can download later.
- pvK12 8y agoBackend is written in JS. I can understand why they chose Node, but why not Typescript? This needs to be maintained and TS >>> JS.
- z3t4 8y agoWhy doesn't Firefox support p2p file sending !? Why do they do with the files I upload !?
- icebraining 8y agoP2P means both machines must be able to talk to each other (occasionally difficult when both are behind NAT) and must be turned on at the same time. Using a reliable intermediary gives some flexibility.
- kgwxd 8y agoWhy not "Mozilla Send"? If Firefox the browser isn't a requirement, the name is confusing.
- mrhappyunhappy 8y agoI was confused too. When it worked on non Firefox browser it was a pleasant surprise. I'm guessing this is just to promote Firefox browser. Wouldn't surprise me if they added higher file limit after usage grows and with it a paid tier :)
- Cyphase 8y agoThe same reason it's Chromecast, not Googlecast.[1] Branding. [1] The protocol is named Google Cast, but all the consumer branding is Chromecast.
- kgwxd 8y agoI was thinking the same thing but in Google's case, Chrome is the dominate browser and most people recognize it as something they already have. In the case of Firefox, it's more likely they'll recognize the name specifically as the browser they don't have and will think they can't use it.
- ghostly_s 8y agoThey'll recognize it as the browser they don't have any maybe should get because it's now positively associated with cool new features like this. :)
- Vinnl 8y agoI think what helps is that there's two (or more) parties to a file transfer: the sender and the recipient. Someone who uses Firefox might start using Send, and then the recipient(s) finds out that they can use it too. And if they're using Send, the might start to consider using Firefox, or to create a Firefox account first.
- ihuman 8y agoDoes Firefox Send work on browsers besides Firefox for sending and receiving files? It's blocked at my office, so I can't test it.
- pizzapill 8y agoThe page states that it'll be available on all browsers and a android app is going to be released later this week.
- fzzzy 8y agoYes. Tested on Chrome, Safari, and Edge.
- tasty_freeze 8y agoOddly, it doesn't work for me (FF 65.0.2, windows 7) -- I just get an inert white rectangle in the middle of the screen. I tried turning off ublock origin and DNT settings, but it still is just a rectangle. It works on chrome, and does not work on IE 11 (win 7 doesn't support edge)
- fzzzy 8y agoThis seems to be a known bug if you have used the old version of send in your profile that may be fixed now. If you try it in a private browsing window and it works, it's probably that bug.
- tasty_freeze 8y agoSure enough -- it works in a private window. Is there a known fix for this, or do I need to create a new profile?
- fzzzy 8y agoIt's been fixed and the fix is deployed to prod. Might need to clear some cache.
- foxhop 8y agoWow, this is really awesome and really cool! First I've heard of it. Just tested it and it worked great. Is it possible to audit the tech? Is Firefox send open source?
- jfk13 8y agoSee https://github.com/mozilla/send/ https://github.com/mozilla/send/
- bjt2n3904 8y agoI don't understand the end-to-end encryption claim. 1. Bob uploads a file, but specifies no password. 2. ??? 3. Sue downloads the file. Best case, Bob's browser encrypts it (with javascript?) before uploading. Either Mozilla provides a key, or Bob sends the key he used. When Sue's browser downloads it, Mozilla sends the key and her browser decrypts it client side. In either case, Mozilla has the password for decryption. This makes a mild barrier to mass scanning content that's uploaded, so at least that's something... but that's little more than a promise I have to trust. Am I missing something? Where is the "end-to-end" encryption? End-to-end means I don't have to trust you (as much). Please don't turn this into a meaningless buzzword... EDIT: I did misunderstand something. Please see timvisee's comment below.
- mimsee 8y agoGenerated by random and applied to the URL hash data that is not sent to the server. Hash data is data in an URL after the hashtag
- timvisee 8y agoThe client encrypts the file that is uploaded, along with some metadata. The key is appended to the share URL provided by the URL, in the fragment/hash, and is never sent to the remote server. Only people having the URL including the secret will be able to download and decrypt your shared file. See https://github.com/mozilla/send/blob/master/docs/encryption.md https://github.com/mozilla/send/blob/master/docs/encryption....
- bjt2n3904 8y agoThanks for the info. Let me see if I understand this correctly. Browsers don't send the anchor tag (ie: with GET requests). FF Send takes advantage of this by using the anchor tag to store the key for decryption. That is kinda novel. You still need to trust the upload client to not leak the key, but I see that you've written a CLI version. Interesting! Thanks for the response.
- NKCSS 8y ago
- omouse 8y agoThe eternal problem of uploading and sharing massive files seems to always have new solutions.
- benawad 8y ago> Key Business Question to Answer: Is the value proposition of a large encrypted file transfer service enough to drive Firefox Account relationships for non-Firefox users. The metrics section is interesting https://github.com/mozilla/send/blob/master/docs/metrics.md https://github.com/mozilla/send/blob/master/docs/metrics.md
- medmunds 8y agoOh interesting. Their two hypotheses (which they will test) are that Send "can drive Firefox Accounts beyond the Firefox Browser" and that it will "will provide a valuable platform to research, communicate with, and market to conscious choosers..." It sounds like they're investigating a premium service offering targeted at privacy conscious users. (The secondary hypothesis covers "revenue" and will be tested by conducting "research tasks ... in support of premium services KPIs.")
- bredren 8y agoMuch of the data I share with friends using dropbox is on time-limited data in the 1-2 GB space. For certain reasons I get a ton of dropbox space, but for my friends, data quotas kick in on even simple files shared like this. I believe this is a primary upgrade mechanism for DB--I'd say this new firefox offer is in competish.
- sumitgt 8y agoIt would be really amazing to build some sort of integration in commonly available WiFi connected scanners and printers. Currently, my scanner conveniently sends me emails with scanned documents. But I have not insight into how they actually store and delete the document on the backend. Would be great if the scanner had the option to upload to Firefox Send and show me a QR code to download it on other devices.
- Shorel 8y agoThis really feels like something the old Opera (not the Chromium version) would have done back in the day.
- all_blue_chucks 8y agoThey did. But it didn't work with NAT so it died.
- m_b 8y agoThis project sucks. Another bullshit firefox.com product that reinvent something existing and well established (eg. Jirafeau or Lufi). I hate so much what Mozilla become.
- crusso 8y ago[Deleting this post as much as able. Didn't realize that the fanboys would be so insulted that I disagreed with Mozilla's marketing policy.]
- svnpenn 8y agothanks for heads up i wont be using the service now
- dhimes 8y agoIs that really a privacy issue?
- deleted 8y ago[deleted]
- Quarrelsome 8y agoof all of the people you could be mad at about privacy you choose Mozilla to be mad at?
- Tepix 8y agoIf Mozilla cares so much about privacy, why don't they disable 3rd party cookies by default like Apple does? That would make a huge difference and while it may break a few sites (i use this setting since a decade or so and have encountered very few), if Apple is OK with that, why shouldn't Mozilla be ok? I'll tell you why: Because they depend on Google's money.
- oftenwrong 8y agoNon-descriptive headline. Borrowing some copy from the announcement makes it better: "Firefox Send: a free encrypted file transfer service"
- maurom 8y agoBeen using it since beta. Props to Mozilla for providing one of the easiest and well thought file sharing services.
- qwerty456127 8y agoHow does it work? Is it P2P or what?
- JohnFen 8y agoThe encrypted file is stored in the cloud. The recipient downloads it from there and decrypts it. P2P would be much better, but this isn't that.
- mtgx 8y agoWasn't it initially P2P and based on the WebRTC protocol?
- JohnFen 8y agoNot as far as I can tell. Mozilla also has (or had, I forget whether it's still a thing or not) a built-in WebRTC client they called "Hello", but that was a different thing.
- qwerty456127 8y agoWhat's the reason it's not made this way or doesn't include WebRTC-based P2P transfer as an option?
- JohnFen 8y agoI have no idea.
- lmedinas 8y agoa bit off topic but here it goes... This is how i think Mozilla can capture more users back to Firefox. By providing "extra" services attached to the Mozilla and Firefox brand will make them a superior product to the end user. Sure it's hard to compete with Chrome but if you offer useful features and services integrated in your Browser i see that Mozilla actually has a chance to compete with Google for the browser space. This is one of the "advantages", if you are a heavy Google user, of Chrome over the competition is that everything is attached to your Google account. Passwords, history, spellers, dictionaries, shortcuts, etc... If Mozilla comes with Send, Notes, Password Manager all integrated in Firefox i see a good way to bring back some of the previous users that switched to Chrome.
- scriptkiddy 8y agoAlong the same lines, a Gmail-esque Thunderbird web service would be amazing. I could finally de-google myself completely if that were the case. Currently, I need to set up my own email hosting through a service like fastmail and then configure a desktop client(like Thuderbird) to use it. A Mozilla Gmail-esque service would remove a lot of the friction there and probably bring in a bunch of users who are tired of google running everything.
- mrtweetyhack 8y agoGood idea. A good email sevrice would actually hurt google while helping Mozilla. Only problem is the "good" part. It's takes lot of effort to offer good service. Hotmail and Yahoomail failed. I haven't seen spam in my inbox in years thanks to Gmail.
- gnud 8y agoFastmail has a nice (and snappy) web interface. So you don't _need_ to set up a desktop client, unless you want to.
- scriptkiddy 8y agoI've used for a contract project I worked on. It wasn't bad, but it was difficult to filter when there was a lot of messages.
- roryokane 8y agoIn the past, I used https://volafile.org/ https://volafile.org/ for sharing files that will be deleted within a week. Volafile doesn’t do end-to-end encryption like Firefox Send, but it allows you to upload files over 2.5 GB. Volafile’s multi-file “room” functionality, with chat, makes it more suited for sharing files among multiple people, while Firefox Send is optimized for sending a single file to a single person or a targeted group.
- cmurf 8y agoRelatively new, are additional expiration options: 1 to 100 downloads, 1 is the default; or 5 minutes to 7 days, 1 day is the default. And an option to protect with a password. Upon expiration, entering the URL behaves the same as if you enter a bogus URL, it's basically denied to have ever existed, i.e. it doesn't say this URL has expired.
- cmurf 8y agoAnother neat feature actually built into Firefox is Take a Screenshot. To the right of the URL field, in the three dots menu. Option to save it locally, or save in the cloud with a URL with some expiration options. Sorta like a pastebin for screenshots. It only takes screenshots within the confines of a Firefox window.
- fzzzy 8y agoGlad you like it (I worked on it). Just a side note, the cloud service will be going away in the future, but the ability to save it locally will remain.
- detaro 8y agoReplacing the cloud bits with Firefox Send integration seems a fairly obvious idea then?
- fzzzy 8y agoThat has been discussed :-)
- robinhood 8y agoThis service is really great and I'm sad to read it will go away - but of course, it makes no sense from a money perspective to keep it free forever. But the initial idea - saving screenshots made by the browser to the cloud is fantastic, and much more convenient than the myriads of SAAS that provide this kind of service.
- SubiculumCode 8y agoI've used firefox send many times since its introduction as a pilot. I applaud its simplicity. The workflow is basically upload, send message/email containing the link, download.
- berry_sortoro 8y agoWhy are they trying to get you into signing in. You need to sign in for sending files that are downloadable more then once and if you want to send more then 1gig. So they WANT you do specifically link your upload to your account, that in fact makes it LESS private. Here we go again Mozilla, they claim they are for privacy but they actually prioritize easy of use and other things over it. Privacy never comes first for Mozilla, they can claim that as much then want. Could write list of things why but I am to lazy right now. As discussed elsewhere they are selling BS as end to end encryption when in fact the key in in the URL so to speak and they are not educating people in that they need to communicate the link (and pw) end to end encrypted as well or its all just made up. People WILL use this to email links use twitter PMs and stuff for it and they will REVEAL EVERYTHING to all kinds of 3rd parties with this deception marketing by Mozilla. They are more about selling your stuff then actually doing it - Sad.
- ajsharp 8y agoSharesecret (my company) provides a similar service, along with a slack extension for anyone who needs a commercial product. https://sharesecret.co https://sharesecret.co
- m4lvin 8y agoThe same idea (e2e decryption key in fragment/hash) is used by the self-hosted Lufi. Public instances are running at https://upload.disroot.org/ https://upload.disroot.org/ and https://framadrop.org/ https://framadrop.org/ and the code is here: https://framagit.org/fiat-tux/hat-softwares/lufi https://framagit.org/fiat-tux/hat-softwares/lufi Maybe someone can comment on how Lufi compares to Firefox Send (performance, usability?) I also think the blog post could explain more why and how the e2e encryption works. Maybe just by showing an example link and then highlight with colors "this part is private"?
- deleted 8y ago[deleted]
- Rafuino 8y agoThis is awesome for sending private documents to family (tax season, anyone?), especially when your family isn't inclined to learn cryptography to set up their own solution. Will be trying this ASAP.
- deleted 8y ago[deleted]
- johnchristopher 8y agoThe npm installation of send is quite easy to set up.
- skrebbel 8y agoIn the not so recent past, HN'ers loved to quote tptacek's legendary rant about how in-browser JavaScript crypto is fundamentally broken[0]. What changed? Is that rant finally outdated? Couldn't Mozilla at any time serve a corrupted JS bundle (with or without their knowledge) which would leak the key somewhere, silently replace the encryption by a noop, etc? I ask out of interest, not skepticism. I much prefer an internet where we can trust web apps to do proper crypto than one where we have to depend on some app store to somewhat adequately protect us. [0] https://www.nccgroup.trust/us/about-us/newsroom-and-events/blog/2011/august/javascript-cryptography-considered-harmful/ https://www.nccgroup.trust/us/about-us/newsroom-and-events/b...
- qrbLPHiKpiux 8y agoAs long as there is a possibility, I say yes - not "if" but "when." Humans are always the weakest link with the internet and someday, sometime, bad code (unknowingly) will be pushed and something will happen to someone.
- serkanyersen 8y agoCouldn't they do the same If crypto code was on server?
- fouadmatin 8y agoSubtleCrypto is a new browser-adopted spec for performing crypto operations natively. For example, instead of using Math.random() for random number generation, you can use https://developer.mozilla.org/en-US/docs/Web/API/Crypto/getRandomValues https://developer.mozilla.org/en-US/docs/Web/API/Crypto/getR... in combination with the SubtleCrypto functions to work with keys securely Your points around a compromised JS bundle are still possible but that has more to do with a company’s deployment/change management setup than JS itself imo
- thinkloop 8y agoDidn't realize it had full support by every browser, even ie: https://developer.mozilla.org/en-US/docs/Web/API/Crypto/getRandomValues#Browser_compatibility https://developer.mozilla.org/en-US/docs/Web/API/Crypto/getR...
- josefresco 8y agoIn one of their videos, the URL is www.send.firefox.com - the others drop the www - is this intentional, a mistake? Why would someone use www before a sub domain like that?
- Causality1 8y agoWhy does it have upload limits at all? Your client encrypts it, the data is sent over your internet connection to someone else's, their client decrypts it. Why would the data pass through Mozilla's servers?
- arduinomancer 8y agoWouldn't you need both clients to be online at the same time to do that?
- Causality1 8y agoYes, but most people are online 24/7 anyway, and that number approaches 100 percent for "two people who need to move a file from one to the other right now". Hosted upload file sharing services are a dime a dozen now. How is this better than slapping something on Dropbox or Mega to send someone?
- rkagerer 8y agoIf I've got this right, the file is encrypted using a secret key which is generated on the client and appended to the anchor in the link, like: http://send.firefox.com/download/<fileid>/#<secret> http://send.firefox.com/download/<fileid>/#<secret> Anyone who obtains the link (e.g. via email interception) gains access to the file. Since browsers don't transmit the anchor when requesting a resource [1], Firefox servers never see a copy of the key. Provided you trust their JavaScript. [1] https://stackoverflow.com/questions/3067491/is-the-anchor-part-of-a-url-being-sent-to-a-web-server https://stackoverflow.com/questions/3067491/is-the-anchor-pa...
- somebodythere 8y ago> Anyone who obtains the link (e.g. via email interception) gains access to the file. True, but, if a third party decides to use the intercepted link to download the file, and you have it set to a limit of 1 download, the file will self-destruct (if you trust Mozilla). This way, the recipient can know that someone has tampered with the communication, which is certainly an improvement over the status quo (email attachments).
- zyngaro 8y agoWhat is the use case of such a tool? Real a question.
- ebg13 8y agoI don't understand what you're asking. The use case is literally in the title ("file transfer").
- Sammi 8y agoOpen source peer-to-peer solution in the browser using WebRTC: https://file.pizza/ https://file.pizza/
- krferriter 8y agoWow that's really neat. Downside is it only works while the page stays open on the uploader's machine, while send.firefox.org uploads the file for a limited time to a central server so you can close the tab before the recipient downloads it.
- liquid153 8y agoIs there a web plugin for this yet.
- old-gregg 8y agoIf relevant Mozilla people are here: Send does not work if "Delete cookies and site data when Firefox closes" checkbox in FF preferences is checked. Even the page doesn't load [1]. It surely is a bug, because I am not closing Firefox. That checkbox is #1 reason I only use Firefox. [1] Developer console log output: "Failed to register/update a ServiceWorker for scope ‘https://send.firefox.com/’ https://send.firefox.com/’: Storage access is restricted in this context due to user settings or private browsing mode. main.js:38:10 SecurityError: The operation is insecure."
- _rlx_ 8y agoThis is a current Firefox restriction: https://bugzilla.mozilla.org/show_bug.cgi?id=1413615 https://bugzilla.mozilla.org/show_bug.cgi?id=1413615
- RJIb8RBYxzAMX9u 8y agoYou should be able to whitelist https://send.firefox.com/ https://send.firefox.com/ with the "Manage Permissions..." button right next to that option. I block _all_ cookies except for a small list of sites (like HN...).
- F_r_k 8y agoSwisstransfer.com is more or less the same, but with 25Gb and no sign up
- hiq 8y agoRegarding the differences, this website does not seem to encrypt the files on the server, and does not provide links directly, so you need to provide at least one valid email address, if only to send the link to you to then send it to the party you want to share the file(s) with. It's also not open-source AFAICT.
- ksec 8y agoI keep seeing comments about Search Revenue and keeping this free. It would be useful if Mozilla is getting more Firefox users out of it, but it likely won't be in any significant number. So what happen once this get popular and waiting to be abused? Just like Mega. Who is going to continue and foot the bill?
- cyphunk 8y agomost abuse mitigated by their limits on the number of downloads allowed and how many days it can stay online. Currently at 7 days max and 100 downloads. If they see abuse they could reduce this further. about revenue, there are so many valuable directions this can go. It could undercut competitors in ways they cannot sufficiently respond to. (google responding in kind would leave them less reason to not add encrypted storage for drive) By stabilizing this platform they can start to build new privacy-enhancing apps on top. Calendar, contacts, etc. With more dependency on the platform, they will find areas where more storage, longer retention, will be income generating. privacy may be the only frontier that can displace google,apple,microsoft.
- DINKDINK 8y agoFor senders and recipients who have execution privileges, OnionShare has: Much lower trust assumptions Functionality for dropboxes https://onionshare.org/ https://onionshare.org/ https://github.com/micahflee/onionshare https://github.com/micahflee/onionshare
- euphoria83 8y agoThis is great! It is a shame that Box and Dropbox need you to be a paying customer to be able to share password protected shared links.
- hieloz 8y agoThat sounds great! Tutanota also provides free encrypted file transfer service.-- Tresorit Send:https://send.tresorit.com/ https://send.tresorit.com/ ,which allows you to upload and share up to 5GB files using the same end-to-end encrypted technology.
- agorabinary 8y agoI'm quickly running out of excuses for still using Chrome...
- Vinnl 8y agoWhile I'm not sure if this is a reason not to use Chrome (you can use it in Chrome as well), trying Firefox is really just a couple of minutes work, and you can easily go back... Here, I'll type the download link for you: https://firefox.com https://firefox.com
- deleted 8y ago[deleted]
- marcus_holmes 8y agoI'm working on a file sharing product, for the niche use case of sharing documents between family and professional providers (lawyers, accountants, etc). Documents are mostly emailed to recipients at the moment (unless they're too large, in which case... um....). The main problem we see is that you end up storing documents in email attachments on your email provider, and using email search tools to try and find documents. Would this end up the same, only with all documents ending up in the Downloads folder? Am I wasting my time working on creating a cloud storage sharing solution, and be better working on a method of organising files on the drive, that can also send them to other people?
- mrdoops 8y agoGenerate a temporary link that, when clicked sends an event to your system to deprecate the link and redirect the user to a presigned S3 download. In my case the file attachment was the product and it was important the system know when someone had downloaded, but a backend system that keeps temporary urls and requests a temporary download link from the file provider is a useful pattern. Nice thing about signed links is your server doesn't have to handle the file - it's between the client and storage provider.
- marcus_holmes 8y agoyeah, I've implemented that temporary link system together with link expiry by date, by access count, and link passwords. I'm encrypting the file on arrival, and storing it encrypted, so it has to route back through the decryption stream. But I could move that to a separate module and replace it with signed S3 if there was benefit.
- 77ko 8y agoWhy have a file transfer for imp docs when you can have a single authoritative source of truth for those docs, along with version history and who changed what. So why not just use Google Drive (or dropbox)? I feel with features like secure file sharing (though only with other ppl with google accounts), reasonably good security[1] and Inactive Account Manager[2] it should work for legal docs. Especially considering Google is going to be around for a while. I would rather use a Mozilla offering but they don't really have too many things for regular consumers outside of firefox and send. [1]: https://myaccount.google.com/security https://myaccount.google.com/security [2]: https://support.google.com/accounts/answer/3036546?hl=en https://support.google.com/accounts/answer/3036546?hl=en
- acnjgg 8y agobeen using this for several months. have used it to send all kinds of files be it malware to large files. it used to accept everything. but now it asks for sign in.. why would they do they though
- JonathonW 8y agoAs I understand it, this "guarantees" privacy by embedding the key in the link-- if that's generated client-side, it never gets sent to Mozilla's servers (assuming they don't go out of their way to grab it via JavaScript) and you can have end-to-end encryption. But, if I'm logged in, it looks like Mozilla's storing that fragment on their servers: if I upload a file from one browser, then sign in on a different browser, I can see the link I generated (including the fragment) from the first browser in my list of uploads, and I can download the file. Doesn't that negate their end-to-end encryption if Mozilla servers have access to the keys?
- dcoates-moz 8y agoThe data that's synced when you log in is also encrypted, with a unique key derived from your Firefox Account called a scoped encryption key. Your key changes when you change your password. We, (Mozilla) don't know your key (and don't want to know it). Disclosure, I implemented the sync feature of Send.
- justinc8687 8y agoThis is cool, but I’m wondering if there is some sort of “secure drop box” equivalent. Basically I generate a set of GPG keys, anyone can post to a web form which encrypts the uploaded data, in browser, using my public key, and uploads it somewhere (my server, s3, Dropbox, doesn’t matter as the private is local on my computer). I could then download the files, decrypt them locally and use them. We get a lot of customers who want to send us secure data (customer info, etc...) and I’d love a way to make it easy for the customer but still secure. Does something like this exist, or is this still a pipe dream? Basically FF send, except I provide a known public key to use, rather than it being generated on the fly, requiring the user to find a way to send it to me out-of-band.
- RoadRunner_23 8y agoFile Transfer https://xkcd.com/949/ https://xkcd.com/949/ Hope Firefox Send solves this ever present problem ;)
- mirimir 8y agoFWIW it works in Tor browser, with no CAPTCHA. Nice.
- solarkraft 8y agoBur Firefox is a browser. Why would you associate this with Firefox instead of making it a Mozilla service? It only leads to the Firefox brand deteriorating even more quickly.
- shivkanthb 8y agoI believe this has been around for while. I used to use https://file.pizza https://file.pizza prior to this
- MrXOR 8y agoNice, but transfer.sh[1] > Firefox send [1] https://transfer.sh https://transfer.sh
- pyyu 8y agoThere's croc with relatively small binary for all non-mobile platforms: https://schollz.com/software/sending-a-file/ https://schollz.com/software/sending-a-file/
- vanous 8y agoTried it and it seems cool. Too bad that there isn't an addon to create a provider for Thunderbird 's filelink.