4 ms·
It is not currently possible to keep files on Securesha.re for longer than 7 days; this is a feature, not a bug. We do not use HTTPS at the moment. As all file
by ghubbard 14y ago
It is not currently possible to keep files on Securesha.re for longer than 7 days; this is a feature, not a bug.
We do not use HTTPS at the moment. As all file transmissions are encrypted, we did not consider it necessary at the moment. A snooper could see the URL of files you have uploaded; however, the password will not be seen.
- STRML 14y agoHTTPS is not always the answer, and Securesha.re is not meant to be a direct competitor to Mega. We are focused less on enabling the sharing of movies & applications and more on the sharing of sensitive documents, private information, and so on.
- exec 14y agoNot using HTTPS is a critical mistake. Adversary can just do MITM attack and send modified code to the user's browser to steal passwords. It's not best idea to share sensitive documents without using HTTPS.
- bascule 14y agoConfirm. This system was obviously designed by people who had no idea what they were doing, which is about the last thing you want in a cryptosystem. Failing to authenticate the JS cryptographic code (TLS would've helped here) makes this system effectively worthless and simple to MitM. A good read on the matter is Matasano's JavaScript Cryptography Considered Harmful: http://www.matasano.com/articles/javascript-cryptography/ http://www.matasano.com/articles/javascript-cryptography/
- mentat 14y agoYou really misunderstand the role of HTTPS in the composition of a secure web page, namely securing the components from MITM against any of the active components which could result in a compromise of the entire page rendering. I have zero faith in the security of your solution if you don't or can't understand this.