BitTorrent Sync security and privacy analysis
2014.hackitoergosum.org
BitTorrent Sync security and privacy analysis
1–10 of 44 posts
Re: BitTorrent Sync security and privacy analysis
#2Bottom line: do not use for sensitive data.
Re: BitTorrent Sync security and privacy analysis
#3> Change of sharing paradigm that introduced this vulnerability happened after the first releases. This may be the result of NSL (National Security Letters, from US Government to businesses to pressure them in giving out the keys or introducing vulnerabilities to compromise previously secure systems) that could have been received by BitTorrent Inc and/or developers.
IF that's true, then it's extremely alarming. I wouldn't use their software to share sensitive files.
Re: BitTorrent Sync security and privacy analysis
#4Re: BitTorrent Sync security and privacy analysis
#5Re: BitTorrent Sync security and privacy analysis
#6Re: BitTorrent Sync security and privacy analysis
#7Re: BitTorrent Sync security and privacy analysis
#8How would this compare to DropBox and other alternatives?
If I understood the article correctly, an MITM attacker (or federal agency) could in theory know that you have a copy of a file only after they have a copy of the same file themselves, by comparing hashes.
Re: BitTorrent Sync security and privacy analysis
#9Has Pulse/Synching protocol been reviewed?
Re: BitTorrent Sync security and privacy analysis
#10From the "Conclusions" section: > Change of sharing paradigm that introduced this vulnerability happened after the first releases. This may be the result of NSL (National Security Letters, from US Government to businesses to pressure them in giving out the keys or introducing vulnerabilities to compromise previously secure systems) that could have been received by BitTorrent Inc and/or developers. IF that's true, the…