15 ms·
Show HN: SlikSafe – A decentralized, end-to-end encrypted alternative to Dropbox
Hey folks,
We are the team behind Slik.
Over the past year, we have been hacking on SlikSafe [1] a Dropbox alternative where all your data is first encrypted on your own device and then stored on decentralized storage.
Some features we're most excited about are -
- multi-device data sync,
- auto-backups via desktop apps,
- search your docs by name or contents with end-to-end encryption,
- easy sharing via email, QR-code or private-link,
- Password-less login using MetaMask/Phantom
We leverage storage providers IPFS and Storj for global redundancy, reliability, and immutability.
You can use our web app [2] and macOS app [3] today. Our desktop app for Windows is currently in beta, and will be launched in early Jan.
You can read our WhitePaper [4] for the technical implementation, or see a quick demo [5] of the product.
Would love to hear what you think.
Arpit, Charvi
[1] SlikSafe: https://www.sliksafe.com https://www.sliksafe.com
[2] Web app: https://app.sliksafe.com https://app.sliksafe.com
[3] macOS app: https://sliksafe.com/downloads https://sliksafe.com/downloads
[4] WhitePaper: https://sliksafe.com/whitepaper.pdf https://sliksafe.com/whitepaper.pdf
[5] Demo video: https://www.loom.com/share/abe133c4ce874655a952a30601e99408 https://www.loom.com/share/abe133c4ce874655a952a30601e99408
- applgo443 5y agoThis is such a cool demo!
- norswap 5y agoHow are files stored ultimately? Something like Arweave or Filecoin?
- charvimittal 5y agoWe currently use Filecoin and Storj for file storage.
- thesausageking 5y agoCan the user chose which network their content is stored on? Are you planning to add support for Sia at some point?
- billpg 5y agoI don't need that. I can just set up an SFTP server and rsync my files to it.
- LikeAnElephant 5y agoThere's the standard Hacker News response I was looking for
- baggachipz 5y agoYou can almost set your watch to it.
- wussboy 5y agoI don't need that. I rsync my watch with nist.gov
- coolspot 5y agoE2E encrypted Dropbox is a Dropbox with EncFS: https://en.m.wikipedia.org/wiki/EncFS https://en.m.wikipedia.org/wiki/EncFS Also, mega.nz
- jeroenhd 5y agoSo, how does this compare to a solution like Bittorrent Sync? And, perhaps more interestingly, why would this become popular where BT Sync failed to live up to the hype? Furthermore, storage can be paid for by crypto. Does this mean the storage is linked to some kind of cryptocurrency, or is there some kind of central payment system that converts crypto into actual value in the system?
- newman314 5y agoBTW this has now been renamed to Resilio Sync. I still use Resilio but am looking for an alternative since development seems pretty dead at this point (no updates for months).
- rspoerri 5y agosyncthing
- XorNot 5y agoDefinitely syncthing - it's incredible. I have all my files managed with it, bare git repositories managed with it, a common shared folder with my partner, my android phone auto uploads photos etc. It all truly just works and it works well.
- apetrovic 5y agoAnother vote for syncthing. I have Synology home NAS, Syncthing in Docker on NAS, Tailscale on both Synology and my laptop so the IP address of the server is always the same, and it works way better than either Dropbox, OneDrive or Synology's own SynologyDrive.
- aborsy 5y agoWhat’s wrong with Synology Drive? It’s working just fine for me.
- Joeri 5y ago
- aarondevera 5y agoVery cool, congrats on launch-- love the use of IPFS and blockchain here
- temp8964 5y agoWho are the targeted users of this? If I want full control of my data, shouldn't I just use a self hosted solution?
- noxer 5y agoI think its supposed to be the off-site backup use case. If you can self-host in a different location you probably dont need it. On the other hand you can use any other service and encrypt your data first if you just need an off-site backup.
- gtsop 5y agoI haven't really understood how the "decentralized" comes into place. My notion of decentralization is the existence of multiple instances managed by unrelated people, such that the service keeps going if one actor falls down. From what I see here, the decentralization lies in the fact that the central service stores the data across multiple servers. So it's not technically speaking a lie, but i would say it is a bit missleading. Edit: If this is/was a trully decentralized tool (which would imply some sort of open source code to host it) i would be stoked
- tata71 5y agoDistributed. Federated.
- sam0x17 5y agoAnother piece of it, I think, is the lack of a central authority that can censor and/or pry into your content. With any well-implemented zero-knowledge solution, this should be the case. Is that maybe a bit misleading? Probably, but a lot of people who search for decentralized are looking for something "off grid" in the sense of no one is watching vs "off grid" in the sense of roll your own grid.
- deleted 5y ago[deleted]
- cle 5y agoDecentralized in this case means you don't trust a single entity to control your access to your data.
- LinuxBender 5y agoMy own interpretation of the definition of decentralized as it pertains to technology would also imply there is not a single super-node you have to boot-strap from. One should be able to host their own boot-strapping cluster of nodes so that if a company goes out of business their nodes will continue to work, software updates not withstanding. Not depending on a single node to me sounds more like distributed like Tor or clustered like Ceph or in some cases federated like Mastadon or Matrix.
- _1tan 5y agoThat is sick, gonna play around with it!
- arpitagarwal 5y agoAwesome! Looking forward to supporting your use case. Feel free to request any feature, would be excited to integrate it. :)
- spicybright 5y agoDon't see how it's better than syncthing, which is free. I don't want a company whose incentive is to make profit to have control over the software.
- trompetenaccoun 5y agoThe website and demo look cool, I like your clean and simple design. The supposed whitepaper however doesn't go into any details at all. It says in addition to Storj the files are also stored directly on "the blockchain". What blockchain? It's not even named. There are no technical details on the encryption process or anything else either. I'd love to like this because imo decentralized private storage is an important issue that urgently needs solutions. But how can you convince people this is better than trusting dropbox when you don't even tell them how it works? And how do you guarantee lifetime storage through a small one time payment? Surely Storj disk space providers aren't going to host files for free.
- deleted 5y ago[deleted]
- arpitagarwal 5y agoThat's some great feedback, trompetenaccoun. Slik's file storage is powered by Storj and Filecoin. About encryption, would love to hear what part you find missing in the 3 protocols for backups, sharing, and multi-device support, mentioned in our WhitePaper. We're constantly improving our WhitePaper to provide as much clarity as possible about our systems and algorithms. We had set lifetime storage for 10 years, and have clarified it on our website to prevent it from being misleading. Thanks a lot for your inputs! :)
- nielsole 5y ago> Slik employs authenticated symmetric encryption. We use AES block cipher in Galois Counter Mode (GCM) with 256-bit key for all of our encryption operations That plus the high level overview of the algorithms seems fair enough for a whitepaper Although I don't get what additional security is gained from using an additional symmetric sharing key in protocol two. Isn't the key gonna be encrypted anyways with the temporary public key from Bob? Also which protocol is used for the asymmetric encryption?
- trog 5y ago> We had set lifetime storage for 10 years, and have clarified it on our website to prevent it from being misleading. If you say it's lifetime and then have to explain it as being 10 years, it's still misleading. Just take out the word 'lifetime'. The chances of me trusting a technology company, especially a startup, especially especially one doing anything on blockchain, to provide a lifetime service is effectively zero. Annual pricing is fine; if you want to go crazy offer two or three years.
- mmastrac 5y agoInteresting approach, but if it's decentralized, can I fully self-host? I feel like this term doesn't really apply when you have a centralized provider. If you have a solution we should be trusting, I would avoid "buzzword bingo" and just be straightforward with your customers.
- whoisninja 5y agohow's it decentralized if 70% of eth nodes are hosted and their software keeps hard forking(backward incompatible) you're just relying more middle-man but giving false sense of p2p network to the end-user no bueno
- miohtama 5y agoThis is an offtopic comment, as there is nothing about Ethereum here, and this person seems to have a grudge against Ethereum based on his comment history.
- whoisninja 5y agowhy does website says this: Login with your Phantom or MetaMask wallet directly into the app MetaMask is ethereum non-sense
- whoisninja 5y agothis is what your profile says: Researching and programming decentralised finance. The code is the law. #defi #solidity #python #vyper #opensource #infosec. Gibraltar i know what you doing in gibraltar, SEC might be interested to know
- seltzered_ 5y agoHow does this compare to solutions like git-annex, where multiple 'remotes' can be defined (whether it's dropbox, gdrive, ipfs, etc.) and you can track the availability of a given file across the remotes?
- aloukissas 5y agoThis is pretty interesting. A while back I was in the early engineering team that built something with similar characteristics (Maginatics > sold to EMC/Dell). It was a cloud (S3, others) distributed file system with variable-length chunks, per-chunk encrypted, with strong deduplication and focus on metadata operation optimization. We were primary storage (vs backup), making it a lot more challenging (performance, app compatibility, real-time collaboration, etc). The demo is pretty interesting, definitely need to read the whitepaper.
- arpitagarwal 5y agoLooking forward to your feedback!
- beedrillzzzzz 5y agoHey congrats, the product looks great! Love to see the rise of e2ee tools. Why did you all decide to go with Storj, a fairly centralized distributed storage aggregator, rather than a decentralized storage network like Filecoin or Sia/Skynet? Who pays for the storage on Storj? For a tool to be decentralized, the user needs a means to pay a node directly and the ability to seamlessly move between providers, ie interchangeable and zero lock-in. Does Storj allow crypto payments and this type of mobility? Also noticed the app runs on Firebase/Google, are there plans to move away from this?
- antoniuschan99 5y agoWhat I'm getting with Web3 is essentially FileCoin or Sia is like an API layer where Companies (DApps?) can build on top of. It looks like this may be an existential threat to the current Tech Giants since their data is centralized whereas these new DApps are not. Looks like they use FileCoin and Storj
- beedrillzzzzz 5y agoYep, but the important part is that 1. Users pay for their own storage, as directly as possible, otherwise they are not in control. 2. Any centralized APIs are fully interchangeable, ideally you can literally select a different gateway in the app, and keep working all within 5 seconds.
- arpitagarwal 5y agoThanks for the great questions! Reliability, performance, and a scalable infrastructure were strong selling points of Storj for us, and hence, we decided to go with them to provide a more seamless experience in terms of data upload and fetch. We also use Filecoin for immutability of user data, and as another layer of global redundancy. Currently, we pay for storage/egress to Storj. Users can pay using dollars/crypto on our platform and we convert it to relevant Storj tokens to pay for storage. It is not automated yet, but yes we plan to automate it soon. Also, Storj does accept Storj tokens as payments. About interchangeability, we plan to provide the migration functionality on our end to users. We started with Firebase/Google because it was easy to setup. However, our team has been experimenting with different blockchains to sync the different file-ids and file-hashes. This would provide even more dApp developers to develop apps on top of Slik. We have a potential fit, and expect that to be integrated in H1'2022.
- cdnsteve 5y agoHow could this be integrated with the Chia project with proof of space? The problem with Chia is storage is filled up with useless data, if you could use your photos or other long term data that would create something great.
- arpitagarwal 5y agoThat sounds like a great idea, cdnsteve. Slik can very easily be integrated with any backend, and we have explored more than 5 different storage backends for the SlikSafe app. Though the current storage backends work pretty well, I'd be happy to connect with the Chia project team. Do you know anyone in their team? and if so, could you connect me with them? Thank you!
- cdnsteve 5y agoI don't know anyone personally but I know Bram Cohen is the creator and know someone that runs one of the pools.
- 0xbadcafebee 5y agoI'm going to start a start-up to build Decentralized bicycles, and use them for a start-up for Decentralized food delivery, and deliver Decentralized meal kits for Decentralized diet plans. Then I can go to a Decentralized gym and Decentralize my sweat, and later take a Decentralized dump in a Decentralized toilet, look down, and marvel at the wonder of modern technological innovation.
- nathias 5y agoVery cool, is it using arweave?
- charvimittal 5y agoWe are using FileCoin and Storj for storage. :)
- nathias 5y agoNice, have you considered making storage free up to a point like web3.storage with filecoin plus?
- arpitagarwal 5y agoYes, to start out, we're providing 2GB of free storage. Beyond that our costs are inclusive of multi-device sync, egress, and storage.
- miohtama 5y agoArweave is not practical, because it is truly immutable and permanent. Updating files is super expensive as all prior copies are kept if I have understood correctly.
- goodpoint 5y agoSyncthing seems provide all the features of Silk and has been around for many years. The main difference is that it uses your devices for storage and never touches somebody's else storage space. And you don't have to pay or use cryptocurrencies.
- charvimittal 5y agoHey, great points here. Our focus is on developing a more consumer-friendly solution like Dropbox which has capabilities like search and collaboration so that anyone can privately store their sensitive data :) Also, we have options to pay in crypto or through credit card.
- no_circuit 5y agoI'm always interested in the business model of a company before using their products. Storj is mentioned as a part of the tech platform. Is the goal of eventually open sourcing Slik essentially is what is described as an open source partner in the Storj whitepaper executive summary [1]? Relevant part here: > Bridging Open Source and Decentralization > In addition to being open source, our new V3 network also financially empowers open source companies by enabling them to generate revenue every time their users store data on the cloud. This supports the open source companies interested in monetizing their product’s use in cloud, while also helping Storj grow adoption of its platform within the innovative open source community. > The new program is enabled by the network through connectors built in conjunction with each open source partner. The connectors track data usage either by storage bucket or by user. When data flows through one of these connectors, the open source company is given credit for the usage and a percentage of the revenue generated flows back to the corresponding project. Partners also earn revenue for bandwidth usage on the network. Storj pays out on average per month [2]: > Egress Bandwidth $20/TB > Repair Egress Bandwidth $10/TB > Disk Space $1.50/TB > Audit Bandwidth $10/TB How much is Slik going to charge to use the app? It almost seems like it the app should be free, or even get paid to use it, if all we are doing is providing the resources for the paying Storj customers. [1] https://www.storj.io/whitepaper https://www.storj.io/whitepaper [2] https://www.storj.io/node https://www.storj.io/node
- arpitagarwal 5y agoThose are some great points, no_circuit. We have multiple storage pricing plans, however, none of them give out $'s to users, because that would be counterproductive for the team at this point. There are parts of the system like the multi-device sync, encryption, cross-platform support, etc. that would need to be factored in. However, reducing $/TB is an area that we plan to explore when all other systems are stable and our unit-economics is net positive.
- pharmakom 5y agoWhat happens if I lose my private keys?
- cookiengineer 5y agoHow is the blockchain structured? Is it shrinkable? In theory, each user would only have a directory of paths and hashes, and everything else would be accessible via ipfs, correct? What kind of encryption are you running? First of all, if there's a simple password like recovery mechanism, it's never post-quantum. Second, if you are refering to the _hashing_ mechanism (merkle trees) in ipfs; I would still have my doubts about the claims. So what kind of Lattice based encryption mechanisms are you running? How do you preserve hash maps to user filesystems, if the data itself is encrypted? If the data itself is encrypted (which it should be), then - by concept - your whole blockchain doesn't make sense because you can literally reuse zero bytes in the whole system. Either that or you would have to implement a key chain where other users can see my private pics, and have a system that allows multiple keys to access the same data blocks. So, from your statements in the "whitepaper" I'd argue that this is a paradoxon, and probably bullshit. Either it's not encrypted at all (more likely) or you don't use a blockchain. If you do both, you have no idea what a blockchain's advantages are, which would make me even less likely to trust your product or vision.
- edf13 5y agoMost of this is on their website and/or WP… They don’t store files on the blockchain, they don’t claim to have their own blockchain.
- detaro 5y ago> They don’t store files on the blockchain, From the whitepaper: > As an extra layer of protection, all your encrypted files are also stored on an immutable blockchain (Yes, that's probably "just" incompetence on the part of the whitepaper author, but if you can't even get a competent author for your whitepaper...)
- turrini 5y ago
- teluride5 5y agoThat's all true, though I suppose the same could be said of Dropbox
- NoGravitas 5y ago
- jalada 5y agoVery good.
- moralestapia 5y agoLol, you got me there for a second.
- noahtallen 5y agoFor those who might not get the reference: https://news.ycombinator.com/item?id=8863 https://news.ycombinator.com/item?id=8863
- dang 5y agoPlease don't do this here.
- clircle 5y agoWhat is the difference betweek Slik and SyncThing?
- mmmmkay 5y agoshouldn't this be open sourced?
- cab404 5y agoso, it's like syncthing, but closed source and "blockchain!"?
- ketzu 5y agoAfter skimming the whitepaper and the storj website, I am not sure which parts are actually provided by Sliksafe. The website tells me I can pay by solana (or even by credit card!), but there seems to be no indication of how much I actually would have to pay. The claims are also not exactly thought out: > No Backdoors > > Since all your files are encrypted on your device, there is no way for us at Slik Safe to access them ever. Even if we wanted, we could never access them. That does not follow from the provided info. Simply leaking the keys in some form would already be enought as a backdoor, as the data is obviously not only stored locally. There seems to be a lot of metadata on sliks side, or is it using some form of encrypted search? Reminds me of "the good ol time" while working on distributed storage, getting annoyed about the filecoin whitepaper and its inaccuracies and missing references (which of course got much much further than our small research project)!
- arpitagarwal 5y ago> I am not sure which parts are actually provided by Sliksafe. The full end-to-end encrypted backup and sharing experience is provided by Slik. We use Storj only for storing the encrypted blobs, or simply as a replacement of S3. > The website tells me I can pay by solana (or even by credit card!), but there seems to be no indication of how much I actually would have to pay. Our detailed pricing page is currently available within our web/desktop apps. You can pay - 0.1 SOL for 10 GB lifetime storage (10 years), or - $4.99/mo for 500GB storage, and so on.. > That does not follow from the provided info. Simply leaking the keys in some form would already be enough as a backdoor, as the data is obviously not only stored locally. This is similar to the problem of leaving your device accidentally open, which unfortunately is a much harder problem to solve. However, we do provide a way for you to remotely wipe a device in case of unauthorized access. > There seems to be a lot of metadata on sliks side, or is it using some form of encrypted search? All your metadata is encrypted on your device before it is backed up to Slik. We provide client side search experience so that Slik is unaware of even the keywords that the user is searching for.
- Eric_WVGG 5y agoHow did you arrive at SOL instead of BTC or ETH?
- Arubis 5y agoI currently use Keybase for this purpose, and while it's not entirely dead yet (slow-but-present maintenance at https://github.com/keybase/client/issues/24636#issuecomment-981931397 https://github.com/keybase/client/issues/24636#issuecomment-...), the writing's been on the wall since Zoom acquihired them. If I can figure out how this works, I'll be happy to give you my money.
- arpitagarwal 5y agoHey Arubis, I was pretty bummed about that acquihire too, but was inspired to build Slik. Please feel free to read through our WhitePaper (https://sliksafe.com/whitepaper.pdf https://sliksafe.com/whitepaper.pdf), to learn how the technology works. We've tried to keep it simple and short. If you have any questions, feel free to reach out at arpit@sliksafe.com. Happy to support your use case.
- yupyup54133 5y ago> SlikSafe – A decentralized, end-to-end encrypted alternative to Dropbox but > https://firestore.googleapis.com/google.firestore.v1.Firestore/Listen/channel https://firestore.googleapis.com/google.firestore.v1.Firesto... This does not pass the sniff test.
- purpleidea 5y agoWhere's the source code? If it's not under a libre license, then it doesn't matter that you are decentralized, control is still centralized in your developer team.
- cabalamat 5y agoWill there be a Linux version?
- olah_1 5y agoMost important thing with this type of product is the options for account recovery. Anything exist around that?
- gregwebs 5y agoHave you looked at the use cases of small businesses? Dropbox being able to decrypt their files can be problematic in some cases. The IPFS-based ransomware protection feature seems not quite right in this context. Storing encrypted data in public could be a negative for some as mentioned elsewhere. Instead, users often need to retain an immutable version history which would also provide similar protection.
- no_time 5y ago>Pay with Solana for lifetime storage (ten years) So which one is it then?
- phs318u 5y agoTen years. Which is also the lifetime of something that only lives for ten years. Such as your files in this solution.
- neximo64 5y agoLooks good until I saw it was on IPFS, which isn't 'forever'. How can you guarantee it will be there for lifetime storage?
- arpitagarwal 5y agoTo ensure lifetime availability of data, we provide redundancy using Filecoin and Storj.
- daqhris 5y agoI saw "password less login" on your homepage, then a smile took over my facial expression. Your product is innovative, that's an advantage over potential competitors with bigger teams and wallets. Another great plus is that you have a walk-through video ready for onboarding new users and visually guiding curious web explorers. Wish you get plenty of success and keep building SlikSafe!
- rdbell 5y agoThis looks amazing dude. Great work. I hope you guys do well.
- applgo443 5y agoWeb3 noob here. Is there a guarantee that IPFS and Storj won't go down or delete a file in the next 10 years? How do you ensure that the files are always stored?
- moron123 5y agoPart of the core motivations of ipfs is to make files last forever. The idea is similar to bittorrent (or any p2p file sharing system). There's no guarantee, but it's more likely that a file will be hosted by one of millions of people, over a handful of corporate servers.
- sirmike_ 5y agoThats cool but I am not paying with some digital coin. But good for people who don't have that hang up.
- adiM 5y agoAny plans for a Linux version? That’s a bit selling point of Dropbox for me as it is one of the few syncing services that have a Linux client.
- charvimittal 5y agoWe are aiming for a Linux launch by end of H1'22
- norswap 5y agoA big question I have is do you pay per GB of storage, or per GB of uploaded data? That makes a big difference when you're frequently updating your files.
- charvimittal 5y agoIt's pay per GB of storage :)
- phs318u 5y agoThis is probably off-topic, but here's what I would love to see: a federated, highly redundant distribution platform where usage requires a contribution of storage. Volume, performance and uptime of that contribution would be rewarded with proportional rights (with respect to available storage, and priority of service). Can such a distributed solution be developed without requiring a blockchain or the mining of coins?
- arpitagarwal 5y agoYes, it can somewhat be done. The net storage costs could theoretically be tending to zero, but might never be zero because of fill-rate per node and maintaining system reliability.
- dustymcp 5y agoWhat happens to cp and banned content ?
- ThinkBeat 5y agoThe problem with decentralized as far as what I have used so far, is that you require a whole host of unknown people to donate X amount of storage space to the network. With IPFS systems I have tried so far you have to struggle to find anyone who has any motivation in storing your stuff for you. Let alone 4 people. Back in the "good old days" a truly distributed P2P system existed to "exchange" mp3 (all legal of course), and other files. People had incentives to share what they and what they got. This is still true for some BitTorrent content but it is not very stable most of the time. (People do not seed for long), though there are incentives to seed a lot. If you dont rely on strangers to store your files and you are paying Digital Ocean S3 or some such it is not really. But sure you can pay multiple providers to store thenm for you.
- woofcat 5y agoIf you are offering a Web App doesn't that imply that you're storing a set of Encryption Keys? If you are does that not allow you to access any files stored with Slik?
- arpitagarwal 5y agoGreat question - we just keep the encrypting keys on the user's device and in-memory. The keys are encrypted using the user's seed phrase that is only known to the user, and not to Slik. Feel free to read more implementation details in our WhitePaper - https://sliksafe.com/whitepaper.pdf https://sliksafe.com/whitepaper.pdf
- hedora 5y agoHow do you prevent yourselves from serving a version of the web app that sends the user’s seed phrase to yourself? (A malicious employee could do such a thing, or you could be legally obligated to do so in order to continue operating in certain jurisdictions.)
- spiderice 5y agoHow is this problem specific to web apps? How do you prevent yourself from serving a compromised iOS/Android/Mac/Windows app? Same answer.
- edoceo 5y agoIsn't this a promise of open source? User doesn't have to get a binary from someone, they could, build from source (given experience+time)
- hedora 5y agoEven for closed source apps, reverse engineering efforts (for sufficiently popular binaries) often find backdoors. This sort of auditing only works because each end user gets the same binary blob. (And if not, there’s a reasonably high likelihood of detection.)
- deleted 5y ago[deleted]
- pketh 5y agoseems v cool and I hope y'all are successful (although I personally prefer to pay for things with regular $s). After reading the marketing site though I'm unclear on whether decentralized storage in this context is the same as a CDN(content delivery network)?
- arpitagarwal 5y agoThanks for the support pketh! We forgot to mention on our current landing page that you can also pay with $ or your favorite currency using our Stripe integration. We'll update that on our website shortly! :) We're using Storj and IPFS as the only storage layer behind user data, not as a CDN.
- _ea1k 5y agoIsn't it impossible to really delete something from ipfs? I'd think that would make this dangerous, as any security flaw would be impossible to fix retroactively. Everything before the flaw would be compromised and can't be reencrypted safely. If a passphrase was lost, the security of every past file would be at risk. This is what has kept me from approaches like this in the past.
- mrharrison 5y agoYou can unpin it, and it will eventually be removed from other non pinned sources.
- sodality2 5y ago>it will eventually be removed from other non pinned sources Hopefully, though, they unpin it.
- Saris 5y agoYes, that's one reason I'm really not sold on storing private data on IPFS and similar services.
- deleted 5y ago[deleted]
- exo762 5y agoCan you really delete anything from NSA servers? Or from Internet in general? For me the problem with IPFS is - it is just not interesting enough. It's not a storage solution, it is distribution and caching mechanism. You can't really upload to IPFS, you can only publish via IPFS - the same way you publish via HTTP.
- bananabernhard 5y agoI am quite confident that the NSA does not have a complete image of the encrypted data in my self-hosted Nextcloud instance. With IPFS they wouldn't even have to do anything, if they sometime in the future were able to break the encryption.
- akvadrako 5y agoAn e2e Dropbox alternative would be great. Though for it to actually count as a Dropbox alternative (to me) it would need: 1) a Linux app 2) an Android app 3) on-demand syncing, aka "smart sync"
- smoldesu 5y agoAre you looking for Syncthing? https://syncthing.net/ https://syncthing.net/
- willis936 5y agoI am looking for syncthing but with an iOS app.
- derbOac 5y agoHas iOS just not been implemented yet or is there a technical hurdle?
- anderspitman 5y agoThere was a propriety implementation a few years ago (written in Rust of all things), but I think it's dead. I think the bigger problem is that both iOS and Android are doing everything they can to deprecate the concept of a filesystem. Android has a history of killing filesystem features, receiving tons of developer backlash, and then hacking in workarounds with reduced performance. I think the writing is on the wall. In my experience, porting general purpose tools to Android is a nightmare. Hopefully something like pinephone gets good enough before things are too bad.
- hagbard_c 5y agoAs long as Android has a Linux kernel running in the background there will be filesystem access. If Google ends up switching to Fuchsia this might change but we're not there yet. General purpose tools seem to run just fine on Android for the most without the need for much porting as can be seen by glancing through the list of patches [1] needed to build a host of packages for Termux. [1] https://github.com/termux/termux-packages/tree/master/packages https://github.com/termux/termux-packages/tree/master/packag...
- guico 5y agoCongrats on the launch, looks really slick! I'm trying to decode the trend for decentralized services. If you have a sec: Q1: In your case, why did you opt for decentralized storage? Q2: Which benefits do I get as a consumer that I wouldn't if this was encoded, but centralized with a lot of redundance? Don't take me the wrong way, really trying to understand where this is all going. Cheers
- throwaway02394 5y agoCongrats on the launch! Your implementation of sharing from the whitepaper scares me. The second that the private key travels anywhere it's no longer safe in my opinion. This is why Signal uses the double ratchet and 1password has their own sharing. Unless I missed something.
- arpitagarwal 5y agoGreat point! We integrated the QR-code and link based sharing into the app to provide a seamless experience for users. However, we also have an email sharing solution already integrated into the app which uses public-key cryptography. This is protected from accidental leaks as you correctly pointed out. Thanks for the feedback, we would update our WhitePaper with the details from above, and also indicate that to users in the UI - so that it scares people less! ;)
- Comevius 5y agoThe whitepaper has no details about an authenticated key exchange like Signal does with X3DH, it just assumes that it already happened, but then the rest of their protocol does not offer any post-compromise security.