Live data from Hacker News

BitTorrent Sync security and privacy analysis

2014.hackitoergosum.org

21–30 of 44 posts

Re: BitTorrent Sync security and privacy analysis

#25
post #13

So if I understand this right, there's probably a backdoor in it? Honestly though, I doubt that you can keep the NSA and FBI out of your system. If they want in, they'll get in, and there's nothing* you can do about it. Having said that, we do need these kinds of solutions without the back doors. Why aren't any software developers from countries where mandatory backdoors aren't a thing building stuff like BTSync? And…

"Having said that, we do need these kinds of solutions without the back doors."

You do have that. Further, you've had it since 2006.

Point duplicity[1] to rsync.net[2].

Cheers!

[1] http://duplicity.nongnu.org/

[2] http://www.rsync.net/resources/notices/canary.txt

Re: BitTorrent Sync security and privacy analysis

#26
Something to keep BT on its edge, but this is hardly a "security analysis" in an established conventional sense. It's a semi-random collection of surface observations from half-a-day of poking around. Sure, some of these may be indicative of serious underlying issues, but they may also be not. E.g. -

> [MEDIUM] Attack vector potentiel : mise à jour automatique (silent update) du client en HTTP sur http://update.utorrent.com

If they check the digital signature on an update package, this is not an issue. If they don't, it is.

Re: BitTorrent Sync security and privacy analysis

#28

What else is there? I personally don't like the idea of not having a two-factor authentication given that someone could theoretically "brute force" the keys... although extremely unlikely in a non-LAN context.

Syncthing is the other option I've used. Setup isn't as easy as Bittorrent Sync though (each computer has to have the node IDs for other computers added manually). And last I checked, there's not a convenient "run in the background" checkbox, so it's not well suited to non-techies yet. But it's got open source going for it. Don't know if it's been subjected to any security audits, but the fact that it eventually could be puts it ahead of Bittorrent.

http://syncthing.net/

Re: BitTorrent Sync security and privacy analysis

#29
post #25
post #13

So if I understand this right, there's probably a backdoor in it? Honestly though, I doubt that you can keep the NSA and FBI out of your system. If they want in, they'll get in, and there's nothing* you can do about it. Having said that, we do need these kinds of solutions without the back doors. Why aren't any software developers from countries where mandatory backdoors aren't a thing building stuff like BTSync? And…

"Having said that, we do need these kinds of solutions without the back doors." You do have that. Further, you've had it since 2006. Point duplicity[1] to rsync.net[2]. Cheers! [1] http://duplicity.nongnu.org/ [2] http://www.rsync.net/resources/notices/canary.txt

setting this up when I get back home. thanks.

Re: BitTorrent Sync security and privacy analysis

#30
post #25
post #13

So if I understand this right, there's probably a backdoor in it? Honestly though, I doubt that you can keep the NSA and FBI out of your system. If they want in, they'll get in, and there's nothing* you can do about it. Having said that, we do need these kinds of solutions without the back doors. Why aren't any software developers from countries where mandatory backdoors aren't a thing building stuff like BTSync? And…

"Having said that, we do need these kinds of solutions without the back doors." You do have that. Further, you've had it since 2006. Point duplicity[1] to rsync.net[2]. Cheers! [1] http://duplicity.nongnu.org/ [2] http://www.rsync.net/resources/notices/canary.txt

but duplicity is a backup program. btsync isn't.
Post reply on HN