It is not clear from the site if the data I give to AeroFS is encrypted at rest. There is a section called "End-to-end Security" that states: AeroFS uses AES-256 with 2048-bit RSA to create secure connections directly from one device to another. Because encryption is end-to-end, even we can't see your data or even file names. But this does not actually tell me in plain terms if you encrypt my data when it's sitting o…
Your data is never stored on our servers in an unencrypted form. Moreover, the data is never stored on our servers at all. In some scenarios (when two clients are both behind aggressive firewalls, for instance) the data may be _relayed_ by our servers, but in those cases it is encrypted (end-to-end) between the devices syncing using their respective public/private keys, so we can't eavesdrop.
AeroFS (YC S10) exits private beta
41–50 of 94 posts
Re: AeroFS (YC S10) exits private beta
#42Earlier quoted context omitted.
Funny bit is that YC companies always miss this. I think ya'll need a launch checklist. (:
I've actually been thinking about putting together a book/list of checklists. 1) Launch 2) Onboarding employee 3) Firing employee 3.5) Firing cofounder(s) 4) Getting hacked 5) Trolled 6) M&A offers 7) Running out of cash 8) Raising (per type of round) 9) Board meetings 10) Annual reporting etc.
Re: AeroFS (YC S10) exits private beta
#43Earlier quoted context omitted.
I'm confused. This makes your servers sound almost entirely useless most of the time. What role do they normally play?
It sounds like they are using their servers as a relay to get around two clients that are behinds NATs.
Re: AeroFS (YC S10) exits private beta
#44Earlier quoted context omitted.
Funny bit is that YC companies always miss this. I think ya'll need a launch checklist. (:
I've actually been thinking about putting together a book/list of checklists. 1) Launch 2) Onboarding employee 3) Firing employee 3.5) Firing cofounder(s) 4) Getting hacked 5) Trolled 6) M&A offers 7) Running out of cash 8) Raising (per type of round) 9) Board meetings 10) Annual reporting etc.
Re: AeroFS (YC S10) exits private beta
#451) I kinda feel like AeroFS has taken so long to come out that Dropbox occupies a huge chunk of mindshare. It's almost as if AerosFS will need to spend a bunch of time answering the "why should I switch" question. That said, I would love to see AeroFS succeed as I am less than keen on Dropbox less than stellar handling of security in the past as well as their general security model.
2) This leads to my second point. AeroFS, please please work with 1Password to do whatever you need to get 1Password+AeroFS working. If this is available, I'm switching right away.
3) Mobile support. Yes, please.
Re: AeroFS (YC S10) exits private beta
#46This is awesome. AeroFS does everything I want in a file sharing system -- I can either run it entirely on my own machines on LAN and potentially VPN, or at a company on a network also not connected to the Internet, or I can use it as a direct Dropbox alternative (although it lacks some mobile clients and API support). I've been using it for ~a year or two in beta, as well as all the other alternatives. I still use D…
Re: AeroFS (YC S10) exits private beta
#47Earlier quoted context omitted.
Your data is never stored on our servers in an unencrypted form. Moreover, the data is never stored on our servers at all. In some scenarios (when two clients are both behind aggressive firewalls, for instance) the data may be _relayed_ by our servers, but in those cases it is encrypted (end-to-end) between the devices syncing using their respective public/private keys, so we can't eavesdrop.
You can go straight peer to peer when behind less-than-totally-aggressive firewalls, using the double open trick used by voip apps like Skype, right?
Re: AeroFS (YC S10) exits private beta
#48Re: AeroFS (YC S10) exits private beta
#49Earlier quoted context omitted.
I've actually been thinking about putting together a book/list of checklists. 1) Launch 2) Onboarding employee 3) Firing employee 3.5) Firing cofounder(s) 4) Getting hacked 5) Trolled 6) M&A offers 7) Running out of cash 8) Raising (per type of round) 9) Board meetings 10) Annual reporting etc.
Sounds like a great series of blog posts too. I'd definitely be interested as some of those topics are rarely discussed.
A lawyer's input would be really helpful for some areas; I'm pretty confident from an entrepreneur's perspective, and from a technical perspective, but while I generally am aware of the laws which apply to me, I'm not qualified or credentialed to give anything approaching legal advice.
It would almost make more sense to do in the Founders at Work style, where you have a domain expert work on each checklist/chapter.
Re: AeroFS (YC S10) exits private beta
#50It is not clear from the site if the data I give to AeroFS is encrypted at rest. There is a section called "End-to-end Security" that states: AeroFS uses AES-256 with 2048-bit RSA to create secure connections directly from one device to another. Because encryption is end-to-end, even we can't see your data or even file names. But this does not actually tell me in plain terms if you encrypt my data when it's sitting o…
Your data is never stored on our servers in an unencrypted form. Moreover, the data is never stored on our servers at all. In some scenarios (when two clients are both behind aggressive firewalls, for instance) the data may be _relayed_ by our servers, but in those cases it is encrypted (end-to-end) between the devices syncing using their respective public/private keys, so we can't eavesdrop.
I really hope it's not a homebrew solution but something based off existing protocols. In either case, since the security and privacy is your primary feature, a full disclosure of hos it works inside is a must.