Earlier quoted context omitted.
#yyyyy would be the encryption key. The webserver end never sees it. It can, however, easily be read via javascript, so mozilla needs to be trusted in any case.
If one were to build a marketing spyware add-on to analyse user traffic from within the browser and send all visited URLs to some remote server, would those sent URLs then possibly contain the anchor?
Firefox Send: Private, Encrypted File Sharing
261–270 of 285 posts
Re: Firefox Send: Private, Encrypted File Sharing
#262Re: Firefox Send: Private, Encrypted File Sharing
#263Re: Firefox Send: Private, Encrypted File Sharing
#264But why?
Re: Firefox Send: Private, Encrypted File Sharing
#265I don't understand why is this called Firefox Send. Shouldn't it be called Mozilla Send?
Probably branding purposes. Even non-techies recognize the Firefox brand. Mozilla – not so much.
Re: Firefox Send: Private, Encrypted File Sharing
#266Is this a Wetransfer killer?
Re: Firefox Send: Private, Encrypted File Sharing
#267Earlier quoted context omitted.
If one were to build a marketing spyware add-on to analyse user traffic from within the browser and send all visited URLs to some remote server, would those sent URLs then possibly contain the anchor?
Yes, but would that matter if these are one-time downloads? You couldn't go get the file even if you did grab the data needed to do so... or am I missing something?
Re: Firefox Send: Private, Encrypted File Sharing
#268I need something like this to send myself links from my phone to my pc.
Re: Firefox Send: Private, Encrypted File Sharing
#269Re: Firefox Send: Private, Encrypted File Sharing
#270Earlier quoted context omitted.
Yes, but would that matter if these are one-time downloads? You couldn't go get the file even if you did grab the data needed to do so... or am I missing something?
The add-on could tell Mozilla which files to keep because it saved the decryption key for those files. Mozilla could then select those files to decrypt, e.g. to prove to authorities that its file-sharing service was not used for illicit purposes. Alternatively, the add-on could filter the IP addresses used to upload the files for potentially sensitive blocks and then tell Mozilla to decrypt the files uploaded by peop…
If you don’t trust Mozilla or you are sharing information that a nation-state attacker would coerce Mozilla into revealing, then you’re already set up to encrypt the file first yourself - at which point you can send it with any service, include Firefox Send.