Live data from Hacker News

BitTorrent Sync security and privacy analysis

2014.hackitoergosum.org

1–10 of 44 posts

Re: BitTorrent Sync security and privacy analysis

#3
From the "Conclusions" section:

> Change of sharing paradigm that introduced this vulnerability happened after the first releases. This may be the result of NSL (National Security Letters, from US Government to businesses to pressure them in giving out the keys or introducing vulnerabilities to compromise previously secure systems) that could have been received by BitTorrent Inc and/or developers.

IF that's true, then it's extremely alarming. I wouldn't use their software to share sensitive files.

Re: BitTorrent Sync security and privacy analysis

#7
I don't use it for sensitive information BUT for my needs this is a great solution that is MUCH better then a cloud based file system. I have my media files for my Phone just BTSync them when I need them and it works like a charm. Also works great for syncing my photos between my computers like photos.

Re: BitTorrent Sync security and privacy analysis

#8
post #4

How would this compare to DropBox and other alternatives?

Well, you're setting a low bar. DropBox is not secure from the government in any way. BTSync is better.

If I understood the article correctly, an MITM attacker (or federal agency) could in theory know that you have a copy of a file only after they have a copy of the same file themselves, by comparing hashes.

Re: BitTorrent Sync security and privacy analysis

#9
post #5

Has Pulse/Synching protocol been reviewed?

They do recommend it as an alternative here and it certainly avoids many of the mentioned issues (relying on other people's architecture, leaking hashes of your data and probably much of the exploitability due to the use of a memory-safe language), though I do not believe there has been a formal review.

Re: BitTorrent Sync security and privacy analysis

#10
post #3

From the "Conclusions" section: > Change of sharing paradigm that introduced this vulnerability happened after the first releases. This may be the result of NSL (National Security Letters, from US Government to businesses to pressure them in giving out the keys or introducing vulnerabilities to compromise previously secure systems) that could have been received by BitTorrent Inc and/or developers. IF that's true, the…

The government has a window into basically all the file sharing services.
Post reply on HN