Live data from Hacker News

Show HN: We built an end-to-end encrypted alternative to Google Photos

news.ycombinator.com

121–130 of 421 posts

Re: Show HN: We built an end-to-end encrypted alternative to Google Photos

#121
post #40

Why does this app need to link my identifiers and contact info to my identity? I would feel a lot more comfortable with this if it didn't collect any data of mine, and you were just storing ciphertext. I don't want an account, and I don't want to give you my name or email.

Hey, we do need some information to get the product to work well. You can see the bits of information we collect, along with the reasoning here: https://ente.io/privacy/#account-data

Collecting my data is a nonstarter for me. The point of e2e is so that the provider doesn't have useful information.

If I have to trust you with my information, you didn't need to bother with the crypto stuff.

Re: Show HN: We built an end-to-end encrypted alternative to Google Photos

#122
post #92
post #76

Earlier quoted context omitted.

I have Synology, actually. Is Synology Photos trustable?

The software with these features is called Synology Moments. I use it and I mostly love it, at the very least as a backup for my Google Photos. My experience is that it works great, provided that you're on your local network. When away from home or traveling, less so. Maybe I could configure things better to alleviate that, I don't know, but I haven't managed to yet. Sharing is less convenient. Trying to share a phot…

For at-home NAS, is Synology the best for recreating Google services?

Re: Show HN: We built an end-to-end encrypted alternative to Google Photos

#123
I’ve been watching this project for a long time and personally am very excited. The fact that it’s #1 on HN today (congrats!) makes me think I’m not the only one.

There are also a lot of valid concerns in these comments about privacy and use of algorithms. A lot of it depends on what you’re looking to gain by adopting a new service/switching away from something else and individual concern.

Personally, I’m looking for a place to store personal photos: friends, family, travel etc. Critical needs - easy sharing ideally not locked into Apple’s ecosystem - not to have my photos mined for advertising and social graph data (most important) - ideally around for the long haul but in my mind this is for sharing, not backup

I’m not particularly concerned about warrants, government surveillance etc. Again for me this is about sharing so the expectation of true privacy is low. Any photos I considered sensitive I would store elsewhere.

For me, the biggest point of confidence I have in this project is that they charge money from day 1 and don’t have a forever free plan. I’m excited about projects that offer the benefits of “social” but where the software, not my data, is the product.

Re: Show HN: We built an end-to-end encrypted alternative to Google Photos

#124

Earlier quoted context omitted.

Actually I'm really curious how you do this. If the photos aren't stored client side, then how do you search? Do you have a thumbnail of every photo client side? Is that enough? I mean ImageNet scores are still pretty low for small/fast neural nets. And ImageNet isn't even representative of real world photos. So obviously to be successful you're going to have to continue training. So how do you do this in a privacy p…

> Do you have a thumbnail of every photo client side In the happy path the files/thumbnails are indexed before they are uploaded. But we are designing a framework that will pull files/thumbnails for indexing if they are unindexed or indexed by older models. > how do you do this in a privacy preserving way Our accuracy will not match that offered by services who index your data on their servers. But there's a trade of…

As someone who has worked on systems like these let me translate:

“You stuff will be private but in return accuracy will be so bad that the UX is gonna suck!”

That’s the key piece people miss when they wanna do anything with ML…that’s it’s a different problem compared to writing code because it’s not about the code anymore, it’s about having great training data!

Re: Show HN: We built an end-to-end encrypted alternative to Google Photos

#125
post #106

Earlier quoted context omitted.

Hey, so the project had initially started off as a self-hostable software (with an option to buy a pre-configured device). We realized soon that it's hard to monetize such a product in the consumer space to the point where it can become self-sustaining. We don't have a problem with offering a self-hosted variant. But given our limited engineering bandwidth we had to take a call on who our target market should be, and…

I get the decision but I think it misses part of the problem: how do you convince people like your mum and dad to start paying for backups and how do you convince them to pay extra for privacy? I suspect the way it usually happens is that somebody your parents trust (like you) tells them to sign up for a privacy-preserving backup service. But who's going to tell them to do that? Do you have the money to pay for adver…

If their service works well and is convenient to use, I’ll be recommending it by word of mouth. In the case of my parents, if I can finally consolidate and de-duplicate the photos from our 3+ Apple Photos collections by pointing the service at “library” folders from a few computers and devices, I’ll be a big fan.

Re: Show HN: We built an end-to-end encrypted alternative to Google Photos

#126

Earlier quoted context omitted.

Am I the only one who never realized you can search "museum" and see your museum photos? Now that you've mentioned it, yes, I'd like to try that. But as a counterpoint to your argument, I've never needed it, and I suspect that a lot of people may not actually be getting the same value propositions that you're getting. On the other hand, Google Photos is Google Photos. But it's often a mistake to compete directly with…

The search is really quite fun to play with, and very useful! I also like searching on the map and seeing where I’ve taken photos. Especially if I’m looking for one particular photo, it’s fun to zoom in from the world map

Thanks for pointing that out. I actually had the opportunity to sync my iPhone photos to Google Photos, but opted to decline. This made me reconsider; cheers.

Re: Show HN: We built an end-to-end encrypted alternative to Google Photos

#127
post #106

Earlier quoted context omitted.

Hey, so the project had initially started off as a self-hostable software (with an option to buy a pre-configured device). We realized soon that it's hard to monetize such a product in the consumer space to the point where it can become self-sustaining. We don't have a problem with offering a self-hosted variant. But given our limited engineering bandwidth we had to take a call on who our target market should be, and…

I get the decision but I think it misses part of the problem: how do you convince people like your mum and dad to start paying for backups and how do you convince them to pay extra for privacy? I suspect the way it usually happens is that somebody your parents trust (like you) tells them to sign up for a privacy-preserving backup service. But who's going to tell them to do that? Do you have the money to pay for adver…

> how do you convince them to pay extra for privacy?

We are hopeful that we will be able to reduce the pricing as we scale up and hit a critical mass.

> who's going to tell them to do that?

We plan to implement a referral program, similar to what Dropbox did, to incentivize existing customers to spread the word.

That said, you do bring up interesting points. To repeat, we aren't averse to the idea of maintaining a self-hosted variant. Just that due to our limited bandwidth we had to choose one direction over another. Having advocates is important and I suppose with time we will have clarity on how to best do this without stretching ourselves too thin.

Re: Show HN: We built an end-to-end encrypted alternative to Google Photos

#128
I’d love for something like this to exist (a fast, clean, well-designed mobile and desktop app for backing up my photos with E2E), but I’d only switch from one of the big providers if it were FOSS and I can bring my own backend target (e.g. S3, SMB, FTP).

In a perfect scenario I could generate my own private key to plug into my client devices and just have everything push to private S3 (and then from there archive to the cheapest, coldest glacier tier after it’s been synced to my home storage).

This to me would not be that complicated to build, but would essentially provide E2E Photostream and a backup of last resort in the cloud.

Obviously (as is the problem with all FOSS) you have the dilemma of how do the developers get paid, which I’m sure is why you went down this yet-another-paid-cloud-provider route instead of what I’ve suggested above.

All that said - I like what you’re trying to build, I could see it being useful to some, but providing E2E photo storage as a direct-to-consumer service is IMHO just asking to be held liable later for what your users store there should you gain any considerable traction.

Re: Show HN: We built an end-to-end encrypted alternative to Google Photos

#129

> two different storage providers in the EU Which ones did you choose and why?

BackBlaze because of their reputation.

Scaleway because of their cold storage offering in a fallout shelter underground that reduces the risk of natural disasters.

Re: Show HN: We built an end-to-end encrypted alternative to Google Photos

#130
post #45

Earlier quoted context omitted.

The source code of the client-side apps appears to be available on GitHub. So if they're bluffing, it won't be too long until someone calls them out on it.

Without a fully described mechanism to confirm that the client you download is not compiled with additional code (i.e. without specifying exactly how the client is compiled, using which version of which compiler, and which compile flags, dependency versions, etc) any kind of "the code seems to be on github" is kind of meaningless.

Ideally they should support reproducible builds so that anyone can confirm that the hash of the app corresponds to a specific tag on the source repository. Unfortunately app stores are making it harder to know what the hash of the app you are installing is, but for side-loading this should still be possible.

For web apps, the situation is even more difficult, but there is a technique called Secure Bookmarks which allows you to confirm that a specific bundle of JavaScript is running (at the expense of some usability):

https://coins.github.io/secure-bookmark/

Post reply on HN