4 ms·
On the contrary. As a user of a service the client is the only piece that I really care about wrt data security. If I can verify that the client isn't secretly
by luser001 14y ago
On the contrary.
As a user of a service the client is the only piece that I really care about wrt data security. If I can verify that the client isn't secretly uploading encryption keys to the server while claiming to encrypt my data, it's a massive win for transparency.
The server is a just an abstracted hard disk. Why would I care how it is implemented?
- lectrick 14y agoBecause some people want to run their own DropBox clone, and titling the post "...goes Open Source" usually (correct me if I'm wrong) implies that the ENTIRE product goes open-source, not just half of it in order to prove that its security is "for real".
- n0on3 14y agoApologies if the title of the post is not clear, I should have specified that it was only about the client. You are right, one of our main goals is to prove that our security is "for real". However, we also hope that our open source client might be useful to other projects, as well as for developers to fork it and implement themselves what is out of our scope.
- marcodb 14y agoBasically, yes, that's the point. Publishing the source code of the client allows the users to be sure that FileRock (Client) isn't "secretly uploading encryption keys to the servers". But please note that the server is not just an abstracted hard disk: it has a role in efficiently checking the integrity of your data, which goes beyond the encryption. For instance, FileRock is able to efficiently detect whether the data has been tampered by deleting a file. Although some of the work is done on the server, the client can counter-check its answers.