4 ms·
It's too bad they focused on commercial closed-source solutions providers. The ecosystem would have really benefited if they had put their efforts to, for examp
by fguerraz 2y ago
It's too bad they focused on commercial closed-source solutions providers. The ecosystem would have really benefited if they had put their efforts to, for example, do the same work with NextCloud.
- kientuong114 2y agoNextCloud has already been analyzed by some great people (https://eprint.iacr.org/2024/546 https://eprint.iacr.org/2024/546).
- xarope 2y agoseafile is open source (https://github.com/haiwen/seafile https://github.com/haiwen/seafile), or at least was, when I looked at it years ago. Definitely a concern when the paper mentioned an acknowledge of the protocol downgrade as of 29th April 2024, yet the latest version on the seafile github is dated feb 27.
- gertop 2y agoSeafile shouldn't be recommended when discussing e2ee cloud solutions. What seafile calls e2ee actually sends your password to the server (except on the desktop application, where actual e2ee happens). They also don't encrypt any metadata such as filenames and hash of the unencrypted content. which might not seem like a big deal but it can accidentally leak sensitive information. https://manual.seafile.com/security/security_features/ https://manual.seafile.com/security/security_features/