5 ms·
> The untrusted device will be able to observe: > File sizes > Which parts of files are changed by the other devices and when I know that cryfs[1] is r
by planede 3y ago
> The untrusted device will be able to observe:
> File sizes
> Which parts of files are changed by the other devices and when
I know that cryfs[1] is resilient to at least the first of these, and possibly the second as well. I don't know if cryfs allows to modify the base directory while the filesystem is online, if it does then it might already be a better solution for syncthing, if you only care about Linux.
On the flip side syncthing could incorporate cryfs's base directory format instead of their home-grown one.
[1] https://www.cryfs.org/ https://www.cryfs.org/
edit:
https://www.cryfs.org/tutorial https://www.cryfs.org/tutorial says the following about concurrent access to the basedir:
"Warning! Never access the file system from two devices at the same time. This can corrupt your file system. When switching devices, always make sure to stop CryFS on the first device, let Dropbox finish synchronization, and then start CryFS on the second device. There are some ideas on how future versions of CryFS could allow for concurrent access, but in the current version this is not safe."
Too bad.
- StreakyCobra 3y agoI'm looking to improve my documents syncing setup. Currently I'm using owncloud, but that seems overkill for just files syncing and it requires maintenance, so I gave Syncthing a look. The "Untrusted device encryption" was not appealing to me because I'm not convinced by the security aspects yet, and also because it is in beta for now. I used gocryptfs [1] in the past and was quite happy with it, so I'm planning to use it on top of Syncthing to have files synced encrypted. As far as I have read this setup (Syncthing + gocryptfs) seems to be used by several people and has already been discussed by gocryptfs' author, who recommended a `-sharedstorage` flag for such use case [2]. Reading [3] I think gocryptfs is more suited for files syncing than cryfs. I'm aware that the metadata (file size, structure, …) of my files are not encrypted but that's a compromise I'm ready to make. I would be happy to hear about opinions about this approach. [1] https://nuetzlich.net/gocryptfs/ https://nuetzlich.net/gocryptfs/ [2] https://github.com/rfjakob/gocryptfs/issues/549#issuecomment-798927899 https://github.com/rfjakob/gocryptfs/issues/549#issuecomment... [3] https://www.cryfs.org/comparison https://www.cryfs.org/comparison