Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

On the contrary.

As a user of a service the client is the only piece that I really care about wrt data security. If I can verify that the client isn't secretly uploading encryption keys to the server while claiming to encrypt my data, it's a massive win for transparency.

The server is a just an abstracted hard disk. Why would I care how it is implemented?



Because some people want to run their own DropBox clone, and titling the post "...goes Open Source" usually (correct me if I'm wrong) implies that the ENTIRE product goes open-source, not just half of it in order to prove that its security is "for real".


Apologies if the title of the post is not clear, I should have specified that it was only about the client. You are right, one of our main goals is to prove that our security is "for real". However, we also hope that our open source client might be useful to other projects, as well as for developers to fork it and implement themselves what is out of our scope.


Basically, yes, that's the point. Publishing the source code of the client allows the users to be sure that FileRock (Client) isn't "secretly uploading encryption keys to the servers". But please note that the server is not just an abstracted hard disk: it has a role in efficiently checking the integrity of your data, which goes beyond the encryption. For instance, FileRock is able to efficiently detect whether the data has been tampered by deleting a file. Although some of the work is done on the server, the client can counter-check its answers.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: