14 ms·
Send: A Fork of Mozilla's Firefox Send
- andredz 5y agoThere's also a CLI for Send (ffsend): https://github.com/timvisee/ffsend https://github.com/timvisee/ffsend
- timvisee 5y agoMaintainer here, thanks for posting! Feel free to ask any questions. Want to try it out? I've a public instance at: https://send.vis.ee/ https://send.vis.ee/ Other instances: https://github.com/timvisee/send-instances/ https://github.com/timvisee/send-instances/ A docker-compose template: https://github.com/timvisee/send-docker-compose https://github.com/timvisee/send-docker-compose
- alexmcc81 5y agoI was wondering why I recognised your name - you're the main developer of ffsend. Thanks for all the work! I really hope you get more people interested in maintaining and developing Send.
- AdmiralAsshat 5y agoWhat level of logging/privacy can we expect from a self-hosted instance? I had faith in Mozilla's commitment to privacy, but I don't necessarily trust some random dude's AWS instance.
- timvisee 5y ago> What level of logging/privacy can we expect from a self-hosted instance? It really depends on who is hosting it. Send itself doesn't really log anything except for errors. A reverse proxy in front of it might be used for an access log, which is default with the docker-compose template for it. Files are always encrypted on the client, and it or its keys are never seen on the server. If you're wondering for the instance I've linked: it runs on Digital Ocean. I have an access log (IP per request, for 24h), I can list encrypted blobs and their metadata (creation time, size), and that's pretty much it.
- SLWW 5y agoHave you had many issues with abuse? For private instances could there be an option for requiring a login before upload?
- timvisee 5y ago> Have you had many issues with abuse? In the last year, I've had 1 DMCA request. And I've blocked one IP that was uploading half a terabyte. > For private instances could there be an option for requiring a login before upload? Not built-in, right now. But you can easily set up HTTP Basic Auth on a reverse proxy that you put in front of it.
- zie 5y agoThanks for maintaining this! I just upgraded our local mozilla copy to your version, works great and was seamless!
- alexmcc81 5y agoDo you have any major new features in mind you would like to implement (assuming you had time + help)?
- timvisee 5y agoI don't have anything planned. But with infinite time, I'd: - add some form of authentication, to limit uploads for example - add a way to preview files on the Send page itself - provide integrations with other platforms - resolve outstanding issues
- StavrosK 5y agoSome simple authentication would be fantastic, so I can run my own instance and only allow myself to upload things.
- timvisee 5y agoThis can already be done with a reverse proxy and HTTP Basic authentication, but having it built-in would be nicer.
- StavrosK 5y agoBut then I'd have to give the password to anyone I wanted to receive files. I want to be able to send files to people but not have them be able to send to others. Maybe adding HTTP basic auth is fine, as I mainly want to keep random bots from finding the service. I'll try that, thanks!
- timvisee 5y agoYou can exclusively configure it on the upload page. It's not super nice, but it works. I have not seen any bots on my public instance by the way. It has been running for more than a year.
- NortySpock 5y agoNaïve question here, but is there a config setting that would work without HTTPS? I run a home server just for internal use and it might be nice to send files via a link for memes, jokes, quick one-shot uses rather than storing it on a samba share, etc, but it doesn't have a public-facing URL for confirming a LetsEncrypt certificate.
- jclulow 5y agoYou could self-sign a certificate, or if your internal URLs use a subdomain of a public domain you control you could use DNS challenges for Let's Encrypt.
- timvisee 5y agoIf you really don't want to use a certificate, just configure the base URL to be a http: address. That should work fine! Feel free to open an issue otherwise.
- tialaramex 5y agoNote that if you do this, rather than actually setting up HTTPS, outside of Send itself a bunch of stuff becomes impossible (you presumably don't want to do any of this stuff, but if you ever do try it just won't work) because you lack Secure Context, and gradually over time you can expect more errors and problems. Already if you give me a plaintext HTTP link I'm going to have to consciously decide that's fine and click past the interstitial warning me it wasn't able to be upgraded to HTTPS, if you use it to inject an image somewhere that's otherwise HTTPS, the image just counts as broken unless I go out of my way to authorise it.
- newman314 5y agoWhy does it say "We don't recommend using docker-compose for production."? I'd like to understand the reasoning behind this. Thanks.
- timvisee 5y agoGood question. I don't have very good reasoning for it, and I haven't put it there. I might need to remove it. Someone asked this before, here is my answer (bottom quote): https://github.com/timvisee/send-docker-compose/issues/3#issuecomment-823525647 https://github.com/timvisee/send-docker-compose/issues/3#iss...
- antaviana 5y agoHow is end-to-end encryption achieved? By storing the password in the URL and not logging the URL when the file is fetched at the receiving end?
- ev1 5y ago#xxxx contents aren't sent to the server at all, if you trust the underlying javascript running in browser.
- timvisee 5y agoEncryption is done with JavaScript on the client. The decryption key is attached as hash to the download URL on the client side as well. When visiting the URL, the key never reaches the server because the hash-part of an URL is never sent and is a local-only thing. So there's no need to strip logging. The client downloads the encrypted blob, and decrypts it on the client. More info: https://www.reddit.com/r/firefox/comments/lqegb5/reminder_the_firefox_family_and_the_firefox/gois1eq/ https://www.reddit.com/r/firefox/comments/lqegb5/reminder_th... And: https://github.com/timvisee/ffsend#security https://github.com/timvisee/ffsend#security
- alert0 5y agoThanks for doing this. I used Send regularly and miss it.
- Ameo 5y agoHey - love this project! I was able to get an instance deployed with Nginx reverse proxy without too much trouble. Password encryption doesn't seem to be working, but that might be some weird header issue thing with the reverse proxy setup and I'm not too worried about it. One thing I was wondering is if/how expired files are cleaned up. I uploaded a large file, set it to expire after 5 minutes, and although I can't download it anymore I see that it's still in the files directory on my server. I glanced through the code, but I didn't see any mechanism for periodically purging expired files or anything like that. Is there something that I missed, or should I just set up a cron job or something to delete all files in that directory older than a week?
- timvisee 5y ago> but I didn't see any mechanism for periodically purging expired files or anything like that. (...) should I just set up a cron job or something to delete all files in that directory older than a week? You're right. Expired files that don't reach their download limit are kept on the server. Due to implementation details there is no 'nice' way to do this from Send itself. If using S3 as storage you can configure a LifeCycle Policy, if using raw disk storage you can set up a cron. See an example here: https://github.com/timvisee/send-docker-compose/blob/master/gc.cron https://github.com/timvisee/send-docker-compose/blob/master/... All uploaded files have a prefixed number which defines the lifetime in days (e.g.: `7-abcdefg` for 7 days expiry). So you can be a little smarter with cleaning up. I should describe this clearly in documentation.
- Ameo 5y agoThanks for the quick reply! This makes sense and works fine. Thanks again for the great project
- skavi 5y agoI was wondering where I had seen your name before, and then after scrolling through your GitHub, I realized it was your Advent of Code 2020 solutions in Rust. Those were absolutely beautiful.
- timvisee 5y agoThanks a bunch! That's awesome to read!
- StavrosK 5y agoThis is fantastic, well done! A very useful service, and I loved it when it was Firefox Send. I'll be sure to use this now.
- mxuribe 5y ago@timvisee I have no questions, but just wanted to thank you for your work on this!!! Thank you, thank you, thank you!
- timvisee 5y ago:)
- andredz 5y agoYou are welcome (poster here :-)). And thanks to you for maintaining a great, and useful, piece of software. I recently needed something like Firefox Send that could have files uploaded for longer than 1 day but no more than 7 days and Send (and your public instance) was perfect for such task.
- matham 5y agoDo you know what led Mozilla to stop this experiment (I'm assuming spam)? Will this not be an issue for your instances as well?
- itake 5y agoThis is self-hosted, so probably easier to apply security through obscurity.
- Black101 5y agothey have a public instance... and just like Mozilla's version you can self-host... but either way we need more services like this.
- TedDoesntTalk 5y ago> we need more services like this I don’t know. The internet had hundreds of file sharing sites at one point. They all suffered fates similar to the epic MegaUpload although with not as colorful founders as Kim DotCom. I don’t see how having them again would be different than last time? https://en.m.wikipedia.org/wiki/Megaupload https://en.m.wikipedia.org/wiki/Megaupload
- rany_ 5y ago> They all suffered fates similar to the epic MegaUpload although with not as colorful founders as Kim DotCom Well it doesn't matter as much in this case because "Send" is a temporary file host.
- mardifoufs 5y agoMediafire is still alive and I think it's the last hold out from the "big" file sharing websites of the mid/late 2000s. Though honestly I don't miss the download limits, timers and adf ly spam that came with them. Common cloud storage (gdrive, dropbox) are much easier to use and share files from, although they require you to be logged in. Send seems to be the best of both world though.
- kickscondor 5y agoSome other WebRTC file transfer options: * https://wormhole.app/ https://wormhole.app/ (my recent fave, by creator of WebTorrent, holds for 24h, https://instant.io https://instant.io by same) * https://file.pizza/ https://file.pizza/ (p2p, nothing stored) * https://webwormhole.io/ https://webwormhole.io/ (same, but has a cli) * https://www.sharedrop.io/ https://www.sharedrop.io/ (same, does qr codes) * https://justbeamit.com/ https://justbeamit.com/ (same, expires in 10 minutes) * https://send.vis.ee https://send.vis.ee (hosted version of this code) * https://send.tresorit.com/ https://send.tresorit.com/ (not p2p, 5 GB limit, encrypted) I track these tools here: https://href.cool/Web/Participate/ https://href.cool/Web/Participate/
- dschep 5y agoThere's also https://snapdrop.net https://snapdrop.net which seems extremely similar to sharedrop.io but has an additional useful feature of letting you send messages which I sometimes use to send links to devices that aren't logged into any service.
- kickscondor 5y agoAh neat! I've added all of the links in the comments here to my list - great to see what's out there and to combine our collections.
- elliebike 5y agoI’m a fan of Kipp! Not p2p, but has optional encryption https://kipp.6f.io/ https://kipp.6f.io/
- fljsdflsdfjdslf 5y agoMissing https://dropbox.com/transfer https://dropbox.com/transfer
- ehsankia 5y agoIs that using WebRTC, or are they hosting the files on their backend?
- tym0 5y agoIs there a way to use ffsend if I drop some basic auth in front of the upload?
- Jhsto 5y agoAfter trying all these WebRTC options and the NAT traversal service (STUN, iirc) always being down, I ended up using IPFS instead. With public gateways from CloudFlare it is very easy to effectively drag and drop files and have them accessible via the IPFS-to-HTTPs gateway.
- TedDoesntTalk 5y agoDoesn’t IPFS have problems with persistence? IOW you can’t guarantee a file will be available?
- nkellenicki 5y agoAs long as you keep your node up and running your content will never disappear. So if you just want to share files with friends I can see this working well - just keep your node available.
- Jhsto 5y agoThere's two persistence types: pinned and unpinned files. Pinned files persist, but someone needs to seed them at least occasionally. Unpinned files get eventually garbage collected. If you want to share a file, you don't need to pin it if the recipient for example tells you when the download is complete. In this sense, all these WebRTC examples are more equivalent to unpinned files.
- dennis-tra 5y agohttps://share.ipfs.io/#/ https://share.ipfs.io/#/ is also very convenient for simple p2p file transfers.
- iagovar 5y agoHow does this work. Does the file need to pass through a server before reaching the other end? or is it streaming directly between sender and receiver? Also, does it need to put the whole file in RAM first?
- 5y ago
- cassepipe 5y agoOh, I forgot about that one. Yet another Mozilla project that worked well that was abandoned. (Remember Firefox OS? https://killedbymozilla.com/ https://killedbymozilla.com/) I know what you're thinking : They did not abandon Rust ! Well I just learned from a post that recently made it to the HN front page that management was considering dropping Rust. The only reason they did not was because of someone who fought hard for it.
- dralley 5y agoIt wasn't "abandoned" it was shut down because it was being used by malicious parties to deliver malware, and worse.
- cassepipe 5y agoCan't any cloud storage service be used to deliver malware?
- tialaramex 5y agoIt depends. Some services are much more suitable than others. Some services are 1:1 ratio. That is, uploading a file results in a download that only works once. So that makes them rubbish for malware, you have to be spear phishing somebody and even then it buys you less than using Tor would. Some services are only encrypted in transit. So bad guys can't intercept or alter the data, but at rest on your server it can be scanned for malware, copyright infringement, whatever the provider wants to scan for. Some services cost money to use which is an obstacle to bad guys who most likely want more money and not to be paying money up front first. Firefox Send was encrypted in situ (the keys live only in clients, so the server doesn't know your keys), it was free to use, and it allowed either unlimited or very large ratios. So that makes it potentially very attractive. On top of which, it has this nice trustworthy Firefox name. Grandma Jenny's kids have told her not to go around installing stuff from just anywhere, but they did tell her _Firefox_ is trustworthy after she got flustered when it auto-updated. How is Jenny supposed to understand that this link to Firefox Send isn't Firefox?
- Black101 5y agoBest HN post in months...
- SubiculumCode 5y agoI'd like to set this up one up of my own servers...
- hojjat12000 5y agoNaive question: The github page says 62% of the languages used in this repo is FreeMarker. I checked the repo and every file I look at is js, what and where is FreeMarker?
- timvisee 5y agoI don't know. Have been asking myself the same question the past month.
- TheDong 5y agoI think it's the locale files, like this one: https://github.com/timvisee/send/blob/master/public/locales/ja/send.ftl https://github.com/timvisee/send/blob/master/public/locales/... If you look at github/linguist, that's what recognizes languages in repos. It has this rule for FreeMarker: https://github.com/github/linguist/blob/32ec19c013a7f81ffaeead25e6e8f9668c7ed574/lib/linguist/languages.yml#L1706-L1715 https://github.com/github/linguist/blob/32ec19c013a7f81ffaee... It seems a .ftl extension means FreeMarker to linguist, so those localizations show up as such.
- timvisee 5y agoIt should be excluded from the stats as it's marked as documentation though: https://github.com/timvisee/send/blob/master/.gitattributes https://github.com/timvisee/send/blob/master/.gitattributes
- TheDong 5y agoIt shouldn't be excluded because that pattern doesn't match any of the files. If you run `git check-attr --all public/locales/foo/send.ftl` with the current .gitattr file, you'll get no attributes. If you update the attr match to `public/locales/**` or `public/locales/**/*.ftl`, then the `check-attr` command above will match it and show 'linguist-documentation'.
- niea_11 5y agoI think this has something to do with the repo being a fork. The parent repo doesn't have this issue. The "languages" list doesn't mention Freemarker on https://github.com/mozilla/send https://github.com/mozilla/send
- voiper1 5y agoI'm liking croc with a CLI on each end.
- psanford 5y agocroc just had multiple major vulnerabilities discovered that required protocol breaking changes to fix: https://redrocket.club/posts/croc/ https://redrocket.club/posts/croc/
- anaganisk 5y agoSo fixed right?
- basemi 5y agoSo it seems: https://schollz.com/blog/croc9/ https://schollz.com/blog/croc9/
- psanford 5y agoYou should be wary of projects that claim to be secure but have a history of game over vulnerabilities.
- psanford 5y agoAs I was saying... another vulnerability was found in croc's Spake implementation in the last day: https://mailarchive.ietf.org/arch/msg/cfrg/icl1AGo62iq8vQM3-NE8XS3bmvo/ https://mailarchive.ietf.org/arch/msg/cfrg/icl1AGo62iq8vQM3-...
- anaganisk 5y agoCrypto is hard, it doesn't wrongly claim its secure. Its a one man show. Isn't that where beauty of open-source lies? Some students were able to get a bug(purposeful) into linux to show how easy it was. Or even the example of Openssl after heart bleed. Some fresh set of eyes look into the code, things get fixed. We have a log of it, developers learn something, and project moves ahead.
- fouric 5y agoThis is excellent! I've been missing Firefox Send ever since they took it down. However, it needs to be hosted somewhere. ...and if I'm going to be using a hosted service, I'd like the ability to easily pay for it (so that it doesn't eventually collapse or resort to shady things like ads), either though donations or microtransactions for bandwidth/storage. Unfortunately, there's no good microtransaction service. Wasn't Mozilla working on one? Where did that go? ...and thus, we've gone full circle. And I'm typing this comment in a Chrome browser, because my company is migrating away from Firefox due to "security issues".
- timvisee 5y agoThis is a comment for my instance specifically, but you might find it nice to know: The https://send.vis.ee/ https://send.vis.ee/ is mostly funded by donations right now. I do not plan to take it down, unless the cost becomes a problem. I'll never resort to ads. If this ever happens, I'll likely show a warning beforehand. Some time later I'll disable the upload page, and will take the rest of it down the week after. Files have a maximum lifetime of a week anyway. So if you discover this when uploading, you can simply switch to some other service. Existing links should not break. There's a donation link on the bottom of the page (https://vis.ee/donate https://vis.ee/donate). But feel free to use it without a contribution.
- U8dcN7vx 5y agoYou can host your own Send, and the host need not exist when there's nothing you are sharing which is right in-line with utility computing as provided by "cloud" hosting companies like Amazon, Microsoft, Oracle, &c. Should be possible for under $5 for a month of Send operation provided low disk space suffices, say under 5GB. Perhaps not micro enough though.
- fouric 5y agoYes, the problem is that it's "not micro enough". The value of this service is low enough that it's not worth it for me to self-host, and the financial overhead of cloud providers is enough that it would cost far more for me to spin up a dedicated instance than pay someone for the fractional cost of usage of their instance. More generally, I want the ability to make microtransactions (substitute "extremely low-friction donations" if you will) for everything that could be "free" but also costs money (bandwidth, compute, storage), because no matter how much free time I have, there will always be services that I could benefit from, but are low-enough-value that it's not worth it for me to self-host or get a cloud host myself.
- neodymiumphish 5y agoI know everybody's posting tons of alternatives already, but I'm curious why https://transfer.sh https://transfer.sh isn't included. It has very simple instructions for encrypting against a recipient's Keybase GPG key, works from the site or command line, and has 14 days of retention. Just curious, since I keep seeing Wormhome mentioned, but I never seem to see anyone mention Transfer (unless it's just a lesser known option and I happened to hear of it early).
- fireattack 5y agoSemi-related, but is GitHub's search by programming language feature broken on this repo? I'm curious about "FreeMarker" being the top language so I clicked on it, surprisingly it returns zero code: https://github.com/timvisee/send/search?l=freemarker https://github.com/timvisee/send/search?l=freemarker So does "javascript": https://github.com/timvisee/send/search?l=javascript https://github.com/timvisee/send/search?l=javascript
- emi2k01 5y agoSearch is disabled for forked repositories in github. It's better to create a new repo and push the code if you want a fork. Search in original repo works: https://github.com/mozilla/send/search?l=javascript https://github.com/mozilla/send/search?l=javascript
- circularfoyers 5y agoThe other option too would be just to clone the repo locally and use grep, find, etc. That seems the simpler option if you just want to perform a search.
- bakje 5y agoOr open the repo in github1s so you don't have to clone anything: https://github1s.com/timvisee/send/ https://github1s.com/timvisee/send/ For more info see: https://github.com/conwnet/github1s https://github.com/conwnet/github1s
- surround 5y agoAn observation. This is the second time today we've had a submission link to github, even though the main repo is on gitlab (the first was https://news.ycombinator.com/item?id=27047243 https://news.ycombinator.com/item?id=27047243)
- forgotpwd16 5y agoHow is ClearURLs' main repo on GitLab when their main site[0] links to both and their docs[1] link *only* to GitHub? [0]: https://clearurls.xyz https://clearurls.xyz [1]: https://docs.clearurls.xyz/latest/ https://docs.clearurls.xyz/latest/
- Izkata 5y agoThe README on the repo itself links to gitlab, including the "create an issue" link: https://github.com/ClearURLs/Addon/#contribute https://github.com/ClearURLs/Addon/#contribute
- surround 5y agoThe AMO page also links to gitlab https://addons.mozilla.org/en-US/firefox/addon/clearurls/ https://addons.mozilla.org/en-US/firefox/addon/clearurls/
- pornel 5y agoThe big advantage of Firefox Send was that it was hosted by Mozilla, and I could trust that Mozilla wouldn't have any backdoor in the service. When the same project is hosted by someone that I don't know, I can't be sure that they won't modify it to peek at the files (I'm not going to perform a full code audit on every page load).
- rcdwealth 5y agoI have been making encrypted file transfer in past with Perl. It would be trivial to symmetrically encrypt a file, use command line or WWW interface to upload it, and construct a link where user just need to enter password to decrypt the file on the fly from the server. Upon download, file would be destroyed. They made a fuss about simple software. More work is to be done to make HTML nice, but I would make it very simple and usable in any browser, including text browsers.
- NeoLaval 5y agohttps://blaze.vercel.app/ https://blaze.vercel.app/