20 ms·
What happened to Firefox Send?
- shp0ngle 6y ago....oh. I have used it a few times in the past for the classic task "move large file between two computers that are next to each other, how the hell do I do this simply", but yeah, I can't see how that would be cost-effective for Firefox.
- deleted 6y ago[deleted]
- DavidSJ 6y agoBetween Unix-based machines on the same network my go-to is netcat. receiver$ nc -l 2000 > file sender$ nc receiver 2000 < file I usually check MD5 sums when I’m done.
- mkayokay 6y agoSCP. simply for the encrypted transmission, and most *nix machines have ssh
- tyingq 6y agoSsh with tar is handy for multiple files. Just be careful you're sending and receiving from the right place. Similar for rsync. (cd /right/place && tar -cf - patt*) | ssh remote '(cd /dest && tar -xvf -)' Of course, you can also use the compression flags with tar.
- DavidSJ 6y agoIt does require having an account on both machines though. I've used nc in situations where one machine is owned by someone else.
- AnonHP 6y agoLooks like you've got the receiver and sender commands reversed. The sender should use input redirection (< file) to read the file and the receiver should use output redirection (> file) to save the file.
- DavidSJ 6y agoLook again. :) That's how I have it.
- therein 6y agoCould easily introduce compression too: receiver$ nc -l 2000 | zcat > file sender$ nc receiver 2000 < $(cat file | gzip -f) But probably something like `rsync -azvP` will be much better in every way yet still quite portable and prevalent.
- Zenbit_UX 6y agoMagic wormhole is your friend
- op00to 6y agoDoes magic wormhole do firewall poking or just pass traffic through a 3rd party host? I couldn’t tell exactly what happens if the direct connection doesn’t work.
- bertman 6y ago>The wormhole send file mode shares the IP addresses of each client with the other (inside the encrypted message), and both clients first attempt to connect directly. If this fails, they fall back to using the transit relay. From https://magic-wormhole.readthedocs.io/en/latest/welcome.html#relays https://magic-wormhole.readthedocs.io/en/latest/welcome.html...
- jwilk 6y agoMagic Wormhole is a security disaster. Do not use if you have other options. 1) By default, authentication key has only 16 bits of entropy. (I wish I was making this up…) 2) There's no good UI to make the key stronger: you can either use, say, "--code-length 16", which makes the receiving code ridiculously long, or provide your own code with "--code", in which case it's visible to other local users via ps(1). 3) Between "wormhole send" and "wormhole receive" on the other side, anyone on the Internet can attempt to intercept the transfer. Conveniently, you can list all currently valid channel ids (nameplates). 4) If the interception succeeds, the attacker can immediately run "wormhole send" with the same code, so that the intended side wouldn't notice anything is off. 5) If the interception fails, the attacker still ruined the transfer. (DoS) All of this would be fixable, if not the maintainer's bizarre insistence on using weak crypto.
- minitech 6y ago> There's no good UI to make the key stronger: you can either use, say, "--code-length 16", which makes the receiving code ridiculously long So you want short, high-entropy keys in a restricted alphabet? That might be tough. Anyway, if it’s not brute-forceable and/because attacks are visible, it’s not really an issue.
- op00to 6y agoEasy ways to copy files between nearby computers: scp The python 3 equivalent of -mSimpleHTTPServer Samba Or maybe I’m missing something.
- Cyphase 6y agopython3 -m http.server
- MaxBarraclough 6y agoTo specify the port number explicitly: python3 -m http.server 8080 (Listening on port 80 may require more privileges.)
- vault 6y agoDefault is 8000
- catswithtail 6y agothe default one is port 8000 so permission should be no problem.
- otachack 6y agoCan also tack on an optional `-d directory_name` to be specific on where to serve from. It's my go to when developing my blog which consists of just HTML+CSS.
- Cyphase 6y ago(To answer the various questions, here's the --help. Also the docs are at https://docs.python.org/3/library/http.server.html#http-server-cli https://docs.python.org/3/library/http.server.html#http-serv...) --- $ python3.7 -m http.server --help usage: server.py [-h] [--cgi] [--bind ADDRESS] [--directory DIRECTORY] [port] positional arguments: port Specify alternate port [default: 8000] optional arguments: -h, --help show this help message and exit --cgi Run as CGI Server --bind ADDRESS, -b ADDRESS Specify alternate bind address [default: all interfaces] --directory DIRECTORY, -d DIRECTORY Specify alternative directory [default:current directory]
- surfsvammel 6y agoToo bad. Never used it myself but it seemed like a useful tool from someone I trust.
- jtbayly 6y agoThis was really funny because I tried to use it for the first time just after it was taken down, but before the announcement. At that time, it loaded a page that made it seem like it was just offline temporarily.
- wodenokoto 6y agoAccording to the press release, it was taken offline temporarily and after that they decided to do it permanently.
- 0-_-0 6y agoThis is due to people sharing malware: https://www.techradar.com/news/mozilla-suspends-firefox-send-service-following-malware-abuse https://www.techradar.com/news/mozilla-suspends-firefox-send... The content can't be scanned server-side because uploaded files are encrypted
- akuji1993 6y agoI mean... Were they really suprised by this? An encrypted file sharing service, of course it's going to be used for sharing malware and illegal content.. I'm not sure what would've been the solution for this issue, but it was pretty clear that that was gonna happen...
- rvz 6y agoExactly. Most definitely bad actors would use this free encrypted file-sharing service. But I suspect that this wasn't even sustainable for Mozilla to begin with. The road to hell is paved with good intentions here.
- therealx 6y agoOnly allowing one time downloads seemed reasonable to stop 1 and 2 stage payloads. Doesn't help exfiltration, but theres so many options for that anyway. One time downloads may be annoying for non-web savvy people, but seemed like a reasonable tradeoff.
- taneq 6y agoThis seems like a feature, not a bug. People can send things privately to you. It's important, therefore, to verify who you're talking to. Maybe instead of blaming it on the lack of server-side malware scans (which are always easily defeated) they could blame it on lack of an appropriate way to build a framework of trust between endpoints?
- mav3rick 6y agoYou're assuming the good case of people sending naive users a virus. But think of two consenting parties sharing cp or something else. It's a legal hell hole.
- rvz 6y agoOh dear. A stunning failure of another Firefox product which was hyped to hot air: [0] Looks like Mozilla really needs to find something to actually be more competitive than their current offerings of 'VPNs', 'File Sharing' and 'Web Browsers'. [0] https://news.ycombinator.com/item?id=19367850 https://news.ycombinator.com/item?id=19367850
- Ensorceled 6y agoI really wish they would focus on safe/private browsing and email and stay the heck out of everything else.
- throwaway33339 6y agoI mean, Send was probably the non-browser product that was useful and solved a problem its users have (sendingfiles.xkcd), and of course they had to axe it. Meanwhile I still have to remove that stupid little Pocket icon every time I do a fresh upgrade
- jrochkind1 6y agoThey gotta figure out a way to bring in revenue with safe/private browsing and email then.
- rkangel 6y agoI once again don't have a good solution for 'how do I email a large file' but https://webwormhole.io/ https://webwormhole.io/ is useful and simple, particularly for sending something big to someone you're video chatting with.
- jbc1 6y agoUp to 2GB https://wetransfer.com https://wetransfer.com
- rkangel 6y agoThank you. Do we trust them and their security approach? Genuine question - it was a major selling point to me that Mozilla were operating Firefox Send. I was happy to give some trust to them and their approach to encryption.
- jbc1 6y agoI'm not sure about any audits or anything they might have had, but they're not a random fly by night. Used pretty heavily by a lot of people involved in media production. Keep in mind that if security is important, you can still self host Send.
- bscphil 6y agoAFAIK they don't have a "security" approach. Files are stored on their servers unencrypted. It's a completely different situation than Firefox Send was - you need to be encrypting the files yourself if keeping your files secure from WeTransfer is important to you.
- WJW 6y agoI used to work there, security was mostly decent with the exception of not encrypting files client side. We advocated for it many times but the founders wanted to keep the UI as simple as possible for users, which means that forcing users to send the encryption keys to the receiver via a secondary channel (ie not via WeTransfer, which would defeat the purpose as we would be able to MITM it) was a no-go. You can always encrypt the files yourself with the method of your choice and then send the encryption key over Telegram/Signal/whatever. The company has existed for over 10 years now and is profitable, so it's not going to disappear overnight or anything. That said, the thing that apparently killed Mozilla Send (becoming a hub for spam and child abuse material) was much easier to handle. The last big project I was involved in was an automated photoDNA scanner to detect suspected child abuse material. It would pull in various lists of hashes of known bad material and flag any matches for manual verification by the department of the Dutch police that handles such things.
- wodenokoto 6y agoFor transferring large files between machines that don’t necessarily have the same clients installed I find file.pizza quite convenient. My understanding is it basically loads a JavaScript BitTorrent client and let’s you transfer using that protocol, so both ends needs to be online, but there is no file size limit, and good support on flaky connections. There’s a few services like this, but I always find file.pizza to be the one that I remember the name of :) https://file.pizza/ https://file.pizza/ EDIT: as other people in this thread, I am also having trouble getting file.pizza to work, in both Safari and Chrome. Maybe it isn’t the answer it used to be.
- tpetry 6y agoHas been shared a lot on hn and i always find it funny that it is simply not working for me. I can't even transfer files between tabs in a single browser nor between browsers on the same host.
- TheNorthman 6y agoDo you have WebRTC disabled? If so, that could be it.
- amelius 6y agoPerhaps your browser stops Javascript in tabs that are not active (?)
- f1refly 6y agoI really want this to work, but every time I tried to actually use it the connection broke a few megabytes into the transfer process. When transferring larger files (>6Gb) it hogs all of my computers 16Gb memory, at which point the oom killer eventually manages to end firefox.
- maple3142 6y agoIt works for small files, but not large files (several GB). I don't know why, but I have experienced unknown failure when transmitting large files.
- 6y ago
- DarkmSparks 6y agoHows firefox doing these days? I've not really used it since it used to run out of memory every few hours, did try it again after they rewrote everything but it was really buggy with half the sites I frequent not working.
- scandox 6y agoI have used it as my main browser for the last 3 years with zero problems. Fast. No memory issues.
- Ensorceled 6y agoI switched to Firefox on Mac in mid 2019, no problems at all. Wish it had chrome style profiles but glad it doesn’t have chrome’s other issues.
- bscphil 6y ago> Wish it had chrome style profiles Could you explain what you mean by this? Firefox does have profiles, and more than one can be active at a time. (There's also the newer containers feature which allows further compartmentalization.)
- Ensorceled 6y agoChrome style profiles that are a 1st class feature; that isn't accessed with a secret url, doesn't require multiple instances of Firefox in my dock, can be toggled between profiles easily, can be easily identified with a icon in the top corner of the browser. I heavily use the firefox containers feature which is awesome.
- headalgorithm 6y agoSee recent discussion: https://news.ycombinator.com/item?id=24508880 https://news.ycombinator.com/item?id=24508880
- jb775 6y agoWhen the service went from unlimited open access to being put behind a login wall, I assumed they were using this tool to pull more users into the Firefox ecosystem (like what google does). I stopped using the service at that point since it effectively lost the privacy aspect.
- blunte 6y agoEither Send is more long lived than I realized, or I have a very different definition of "legacy" From the Mozilla Blog: ... we are announcing the end of life for two legacy services that grew out of the Firefox Test Pilot program: Firefox Send and Firefox Notes.
- bscphil 6y agoNo, you remembered correctly. > It was launched on March 12, 2019 https://en.wikipedia.org/wiki/Firefox_Send https://en.wikipedia.org/wiki/Firefox_Send
- boomboomsubban 6y agoThey're calling the two programs something that was carried on after the discontinuation of Firefox Test Pilot, not saying it's outdated software. Like the "legacy of our forefathers." Probably not a great word choice though.
- robertlagrant 6y agoIf you speak to Microsoft, it means "Stuff that isn't Microsoft software".
- fzzzy 6y agoThanks. This made me laugh out loud.
- 40four 6y agoToo bad. I really enjoyed using it while it was up. The code is open source, and they have docs on how to set it up for self hosting. I wonder if there is a chance some active forks might live on? https://github.com/mozilla/send https://github.com/mozilla/send https://github.com/mozilla/send/blob/master/docs/deployment.md https://github.com/mozilla/send/blob/master/docs/deployment....
- gergely 6y agoTresorit has the same functionality: https://send.tresorit.com/ https://send.tresorit.com/
- gruez 6y agoRequires your email
- unicornporn 6y agoJust fill that field with crap. Not required to get the files sent.
- feralimal 6y agoresilio too
- sdan 6y agoTried self hosting the day it came out. Had no luck, but i'm sure its possible given the docs.
- werdnapk 6y agoI used this service fairly often with clients to send me large files... pretty much drag and drop and send me the link to the file. I thought it was great. I guess I'll check out some of the alternatives listed in the comments here now.
- kace91 6y agoI really don't understand it. - Content was used to spread malware/illegal content - It was not profitable How are those two things something you find out after the fact? What was the reasoning for launching the product in the first place?
- johannes1234321 6y agoMozilla Foundation, as owner of Mozilla Corp, is a non-profit. Thus the second argument is not that important. Also a single feature can be unprofitable if it helps to drive the related products. First argument is more relevant, I see it as underestimated the risk there and coming out of a technical experiment ... That all said: Mozilla Corp's "focussing" doesn't convince me.
- elithrar 6y ago> Mozilla Foundation, as owner of Mozilla Corp, is a non-profit. Thus the second argument is not that important. “Non-profit” doesn’t mean “don’t make profits” or “set a pile of money on fire”.
- kace91 6y ago> Mozilla Foundation, as owner of Mozilla Corp, is a non-profit. Thus the second argument is not that important. I included that argument because it's mentioned explicitly by them: > as we weighed the cost of our overall portfolio and strategic focus, we made the decision not to relaunch the service.
- heftig 6y agoThis doesn't imply the benefits that were weighted against the costs were monetary.
- boomboomsubban 6y agoI assume they expected some use to spread illegal content, but the ratio of illegal use to accepted use was far different than their expectations. Presumably the reason to launch it was to advertise Firefox by providing a useful tool that encourages linking to others.
- sstanfie 6y agoI switched to croc (https://github.com/schollz/croc https://github.com/schollz/croc) to send large files. Works great across macOS and Windows. It's synchronous, one-time, so not a fire-and-forget system. But quick for large files (sending custom disk images for Raspberry Pi).
- loraa 6y agoIt's Firefox running after Brave. They are having a hard time convincing normal people that they are not Chrome and need a gimmick.
- saos 6y agoWhat a blow. I loved it.
- toyg 6y agoThis is one thing they could have done better in partnership with someone whose main business is hosting and transferring files. I said it yesterday: Mozilla and Dropbox should talk. Alone they will perish, united they’ll be a real alternative to FAANG.
- gsich 6y agoNetflix and filesharing?
- SamuelAdams 6y agoInteresting. I thought it was discontinued due to malware and hackers using it. I wonder if they were ever able to successfully mitigate these threats with an encrypted file sharing service. If they did, the community ought to know so other projects in the future can learn from Mozilla's efforts. [1]: https://www.zdnet.com/article/mozilla-suspends-firefox-send-service-while-it-addresses-malware-abuse/ https://www.zdnet.com/article/mozilla-suspends-firefox-send-... [2]: https://cybersecuritymag.com/firefox-send-suspended-hackers-malware/ https://cybersecuritymag.com/firefox-send-suspended-hackers-...
- esquivalience 6y agoThat's also what it says in the linked explanation contained in the article.
- blooalien 6y agoAnd mere minutes after reading this, what should come in on my newsfeed? https://news.ycombinator.com/item?id=24503077 https://news.ycombinator.com/item?id=24503077 Another tool for sending encrypted files from one machine to another. Viva la Hacker News!
- mc32 6y agoFile.pizza is also p-p file defer in the browser, though I liked send from Mozilla since it was integrated.
- TedDoesntTalk 6y ago> Unfortunately, some abusive users were beginning to use Send to ship malware and conduct spear phishing attacks. This summer we took Firefox Send offline to address this challenge.
- redm 6y agoI think this comes down to the fact that deploying an app and a platform are very different things.
- neilsimp1 6y agoHahahaha. I have always thought this looked like a great product but never really had a need for it. I had a file slightly too large to email last night and thought I'd try FF Send for the first time ever, only to be greeted with `Service Unavailable`. It's a real bummer this is going away, and I hope this isn't a sign of more to come.
- haezee 6y agoOkay, but what happened?
- isodev 6y agoI was under the impression Firefox Send was one of the upcoming paid service offerings. At least, that we were seeing the free service and waiting some premium features to be released later on. It will be missed, it was a really easy and intuitive solution for file sharing,
- m000 6y agoI was really hoping this would be the case. Sync + Send + Lockwise would be a bundle of services worth paying a subscription for. Provided that they also made them available on Chrome rather than using them as lock-in features. But there seems to be zero plans towards financial independence for Mozilla Corp. The management board appears to be all too cozy with Google funds lining their pockets. A financially independent Mozilla Corp. would probably mean less money for them.
- nickjj 6y agoThis was a great service for transferring 1 off files between 2 people (such as 500mb wav files for podcast episodes which is what I used it for). As it turns out, you can get similar behavior with Dropbox. The person sending the file doesn't need a Dropbox account either. You just send them a URL and then they have permission to upload the file. The only extra step vs Firefox Send is you as the receiver need to delete the file after you've downloaded it. Technically that's optional but in my case that's what I wanted to do.
- brunoqc 6y agoThe downside with Dropbox's way is that a lot of people using the link will think that they need to register an account. I think the link offers you to create one but it's not clear that it's not required.
- llagerlof 6y agohttps://transfer.sh https://transfer.sh
- AnonHP 6y agoTangentially, I wonder what's happening with Lockwise. [1] It also seems to be languishing without significant improvements. I was expecting it to be a competitor, at least on mobile, to the likes of Bitwarden, 1Password, and other solutions. [1]: https://www.mozilla.org/en-US/firefox/lockwise/ https://www.mozilla.org/en-US/firefox/lockwise/
- arkitaip 6y agoI'm so happy I decided to move away from Chrome's password manager and Firefox Lockwise and instead use Bitwarden.
- fergbrain 6y agoThe challenge I have is when someone non-technical needs to send me a very large file. I’ve resorted to spinning up a pureftp server in docker and having them drop it there.
- rogerdpack 6y agoIt's like allpeers all over again?
- CodinM 6y agoFrom their Github repo, Deployment: "Optionally telnet, to be able to quickly check your installation"
- zxcvgm 6y agoTo be honest, I think some form of abuse was bound to happen. Your files are encrypted client-side with JavaScript before uploading, so to the server it's just an opaque blob. Out of curiosity, I did some technical analysis¹ of how your files were being encrypted to see if they were really secure and as a side-effect, also wrote a Go client for it. An interesting property I did discover about the way the encryption keys are derived is that the scheme allows you to delegate an oblivious third-party to download the blob for you, without actually revealing the file contents to them. ¹ https://irq5.io/2019/05/14/data-encryption-on-firefox-send/ https://irq5.io/2019/05/14/data-encryption-on-firefox-send/
- fireattack 6y agoMight be a stupid question, but why server can't see the secret key? You said that "note that URL fragments are never sent to the server", which is true when uploading the file. But when someone is downloading the file, they need to use this full URL with secret key right? By then, the server will get the key and can decrypt the file themselves.
- hiq 6y agoSee the post that OP linked: > Note that URL fragments are never sent to the server. They are often used for page anchors, and sometimes to keep track of local state in SPA. Also see: https://en.wikipedia.org/wiki/URI_fragment#Basics https://en.wikipedia.org/wiki/URI_fragment#Basics
- fireattack 6y agoThank you for the info. I thought it's setup specific, didn't know anchor string is never sent to servers in general.
- wistlo 6y agoWow, this thread just turned into bookmarked resource for file sharing. Best compilation I've seen recently. I get CPU usage with both Chrome and FF, running a consistent 10-20% for what seems no good reason. Windows task manager "power usage" also indicates FF as "very high" in "power usage", which might be related to GPU use. Windows seems happier with Chrome's power usage. I detect no difference between the two in my Z-book's fan or CPU temps (which are always warm, and warmer if I don't run atop a cooler base). FF has significantly improved over past 18 months in response and load times for a complex heavy front end UI for Siebel, matching Chrome's response time.
- alex_duf 6y agoI wish we could get every major OS to work on an open standard for file transfer from device to device (locally).
- kevincox 6y ago+1 AirDrop is pretty cool but proprietary. Android Beam looked promising but Google killed it for something proprietary. Samsung had an updated version that used WiFi Direct, but I don't know if it was open. It seems that something that was somewhat plugable would be very useful. - NFC or bluetooth for setup. - Bluetooth, Wifi Direct or Internet for transfer. Mesh networking would be cool as well but I don't think it is actually needed for the MVP.
- timvisee 6y agoSad! Developer of `ffsend` here. I've built `ffsend` as CLI tool for Send to securely share files from the command line. It has been a great success! Thanks Mozilla, for building and providing this amazing service! For the interested: https://github.com/timvisee/ffsend https://github.com/timvisee/ffsend I'm currently hosting a public Send instance myself so ffsend keeps working. Let's see how long I can keep this going (and funded). It's available at send.vis.ee .
- dmix 6y agoWas this shutting down as surprising and out-of-left-field to yourself as someone more closely connected to the project, as it seems to me?
- timvisee 6y agoPretty much. They suddenly took it down for 'maintenance'. The relaunch was delayed. Mozilla released a statement on laying off 250 employees. That's when I figured it wouldn't come back online again.
- sfink 6y agoI don't have any specific knowledge, but my general impression was that malware was a very real issue that nobody could come up with a realistic response to. Other than that, it seems like Send was a breakout success. (I work for Mozilla, but mostly on the JS engine.)
- abnercoimbre 6y agoWith the utmost respect, can somebody please tell if anyone thought of requiring a Firefox account? Or charge $2/mo and go from there? Products usually iterate on design and security, no? Not just give up right away? Some of us recommended a Firefox+ service that bundles Firefox Send, the VPN, etc. and charge a monthly premium. I would've paid a lot of money. Nothing makes any sense looking from outside!
- angel_j 6y agoMozilla sucks at software. They are prescriptive, and always changing. They practice the worst of open source (give today, take tomorrow, user no choice, auto-updates), and they cannot keep up with enterprise in their own domain.
- surround 6y agoDiscussion yesterday: https://news.ycombinator.com/item?id=24508880 https://news.ycombinator.com/item?id=24508880
- systems 6y agowhat are the good alternatives, I spent sometimes on google, and most services seem to required monthly subscription I need to send large file securely sporadically , I cant like pay for like 10 usages etc .. as long as its not time bound
- gigatexal 6y agoGet paid by Google; kill services like Google.
- dpc_pw 6y agoThe fact that you need a 3rd party service to send a file between two computers is a failure of the Internet as a whole. Instead of addressing it, the technical community as a whole just keeps putting bandaids on it.
- napolux 6y agoWe have FTP, but are you willing and/or able to manage an FTP server open to the Internet on your personal pc? I can do it, but FFS I won't.
- Sohcahtoa82 6y agoWhat makes it difficult are two problems: - Dealing with NAT - Security Making a protocol for connecting to another machine and sending (or requesting) a file is easy. We solved that a couple decades ago. But how do you do it when both ends are behind NAT? UPNP was supposed to solve this problem, but not everyone uses UPNP, and it's pain in the ass to deal with port forwarding, also, good luck trying to walk grandma through setting up a port forward on her router.
- dpc_pw 6y agoI know. And it's a failure of an Internet and software ecosystem as whole. Somewhere between 2000 and 2010 we just accepted how much of fiasco and garbage everything have became.
- edwincheese 6y agoWe have built an alternative to Firefox Send. End-to-end encrypted, faster, more space, and more features coming. https://encl.io https://encl.io