Live data from Hacker News

Firefox Send: Private, Encrypted File Sharing

send.firefox.com

261–270 of 285 posts

Re: Firefox Send: Private, Encrypted File Sharing

#261
post #59

Earlier quoted context omitted.

#yyyyy would be the encryption key. The webserver end never sees it. It can, however, easily be read via javascript, so mozilla needs to be trusted in any case.

If one were to build a marketing spyware add-on to analyse user traffic from within the browser and send all visited URLs to some remote server, would those sent URLs then possibly contain the anchor?

Yes, but would that matter if these are one-time downloads? You couldn't go get the file even if you did grab the data needed to do so... or am I missing something?

Re: Firefox Send: Private, Encrypted File Sharing

#265
post #4
post #2

I don't understand why is this called Firefox Send. Shouldn't it be called Mozilla Send?

Probably branding purposes. Even non-techies recognize the Firefox brand. Mozilla – not so much.

eh, what's current Firefox market share? I would not bet my money many non techies recognize Firefox at all, it's pretty niche nerd product for people with addon fetish, rest of the world just use Chrome/IE/Edge

Re: Firefox Send: Private, Encrypted File Sharing

#267

Earlier quoted context omitted.

If one were to build a marketing spyware add-on to analyse user traffic from within the browser and send all visited URLs to some remote server, would those sent URLs then possibly contain the anchor?

Yes, but would that matter if these are one-time downloads? You couldn't go get the file even if you did grab the data needed to do so... or am I missing something?

The add-on could tell Mozilla which files to keep because it saved the decryption key for those files. Mozilla could then select those files to decrypt, e.g. to prove to authorities that its file-sharing service was not used for illicit purposes. Alternatively, the add-on could filter the IP addresses used to upload the files for potentially sensitive blocks and then tell Mozilla to decrypt the files uploaded by people from such blocks, e.g. in an attempt to engage in corporate espionage (of course one shouldn’t use third-party services for sensitive files in the first place, but if you have to use a third-party service, certainly an ‘open-source’, ‘private’ and ‘encrypted’ one from such a reputable company as Mozilla, right?)

Re: Firefox Send: Private, Encrypted File Sharing

#270

Earlier quoted context omitted.

Yes, but would that matter if these are one-time downloads? You couldn't go get the file even if you did grab the data needed to do so... or am I missing something?

The add-on could tell Mozilla which files to keep because it saved the decryption key for those files. Mozilla could then select those files to decrypt, e.g. to prove to authorities that its file-sharing service was not used for illicit purposes. Alternatively, the add-on could filter the IP addresses used to upload the files for potentially sensitive blocks and then tell Mozilla to decrypt the files uploaded by peop…

Several of the alternatives linked in this post’s comments make no effort to encrypt at all; they simply try to con users into sharing files with their intermediate server in plaintext, as if somehow that’s an acceptable thing to do.

If you don’t trust Mozilla or you are sharing information that a nation-state attacker would coerce Mozilla into revealing, then you’re already set up to encrypt the file first yourself - at which point you can send it with any service, include Firefox Send.

Post reply on HN