Live data from Hacker News

Show HN: File.io – Ephemeral file sharing

file.io

31–40 of 92 posts

Re: Show HN: File.io – Ephemeral file sharing

#31
post #15
post #13

tl;dr from the FAQ: Q: "Why should I trust you?" A: "Because you should! We're good people! Honest!" I'd love to trust a service like this, but there's no credible effort to actually establish that trust.

So encrypt client-side?

Okay, but then the receiver has to know how to decrypt. Kind of narrows down who I can realistically send files to.

Re: Show HN: File.io – Ephemeral file sharing

#32
post #14

Data remanence is a really hard problem. Are you sure this lives up to your claims that "the file is completely deleted without a trace"? How are you storing them? Do they ever hit e.g. an SSD in plaintext?

Claims are irrelevant, data breaches happen all the time.

If you are concerned about the confidentiality of a file then use encryption or don't upload it to the internet.

Re: Show HN: File.io – Ephemeral file sharing

#33
post #13

tl;dr from the FAQ: Q: "Why should I trust you?" A: "Because you should! We're good people! Honest!" I'd love to trust a service like this, but there's no credible effort to actually establish that trust.

Now it says > file.io is a project of humb.ly. It was created simply out of the joy of trying to build cool things on the internet, and we thought it may be useful for others. We take privacy very seriously and do not save any data once it has been deleted. But going to humb.ly still doesn't really get me to trust you, there's not even any identifying info on that page. Two projects, one discontinued and one -- it se…

It said that before, too — I was paraphrasing. "humb.ly" is a more trustable name than, say, "Megaupload", but they can say whatever they want.

What I want is some assurance like "The EFF has complete read-access to our platform and maintains a continuous independent audit of these services to verify that we comply with our own privacy assurances." The EFF is probably not the organization to do such a thing, but that's kind of what I'm looking for.

Re: Show HN: File.io – Ephemeral file sharing

#34
This is nice service and I like these kind of microservices, but I miss security here. I think you should consider some integration with services such as metascan-online.com(I work for company who is creating this), or other services for file scans. I always try to answer following question with services like this:

How can I know, that there is no malware in the shared file?

Re: Show HN: File.io – Ephemeral file sharing

#35
post #2

I built this site and appreciate any feedback from the HN community

Nice service. You should considered a default expiration (a week?) to lighten the load, and an option for multiple downloads (?dl=3) so the first n get a copy or multiple tries if corrupted.

Also, you don't keep logs but what about your cloud provider? What guarantees can you make about them, and what responsibility do programmers have to explain the risks to the public? It seems wrong to say "anonymous and secure" without some qualifiers: you must use https, unencrypted files might be copied by the cloud provider, etc...

Re: Show HN: File.io – Ephemeral file sharing

#36
post #31
post #15

Earlier quoted context omitted.

So encrypt client-side?

Okay, but then the receiver has to know how to decrypt. Kind of narrows down who I can realistically send files to.

If you are that concerned about security you should be willing to deal with the effort of encrypting it client side and understanding how to also decrypt on the receiving side.

If paranoia is this high, why would a security policy text on a web page make any difference? They could claim anything they want, but you wouldn't have any idea if any actual encryption was happening, so best to do it yourself.

Re: Show HN: File.io – Ephemeral file sharing

#37
post #29
post #16

Earlier quoted context omitted.

I was using https://usetorpedo.com (similar service) before it shut down. Probably some lessons to be learned from them. While I didn't use it super often, when I did want to use it, it was very valuable. Thanks for building this!

Maybe it failed because USE TOR -> PEDO :)

Lol at the downvotes. Not my fault that a privacy oriented filesharing service has a domain with the words use, tor, and pedo all in a row.

Re: Show HN: File.io – Ephemeral file sharing

#38
No privacy policy, no technical details on how the files are stored / "securely deleted" / etc., no definition of what "illegal" means (i.e. which national/state/provincial/local/etc. jurisdiction is relevant for this site). Looks cool, but I'm certainly not touching this without client-side encryption until those missing things are made not-missing.
Post reply on HN