Readworthy thread on Reddit regarding Proton’s misleading marketing of Proton Drive. (Not as bad as Nextcloud’s E2EE marketing but far from something I expect from a company like Proton.)

reddit.com/r/ProtonDrive/comme

#e2ee #proton #protondrive

Follow

@karlemilnikka Can you share a link to Nextcloud's bad E2EE marketing? Or anything that explains issues etc with E2EE using Nextcloud? It would be appreciated for my learning.

@hehemrin [1/3] I’d love to. In short: the E2EE extension was marketed as an enterprise grade solution where folders could be shared between users (the latter is still mentioned in the very first paragraph, just to be contradicted in the following paragraph). The extension was also supposed to support offline recovery and HSMs. Back in 2020, these features were marketed as if they existed(!). See web.archive.org/web/2020020402

@hehemrin [2/3] However, these features have never even been worked on. Earlier this year, Nextcloud GmbH started calling these features “roadmap features”, stating that that the E2EE extension was under constant development. But not even that is true. Nobody is working on these roadmap features! And nobody will start working on them for a foreseeable future (source: github.com/nextcloud/end_to_en).

@hehemrin [3/3] I totally understand if there aren’t resources to work on the project. It’s a free and open-source project after all. The problem is that Nextcloud GmbH’s deceptive marketing gives new Nextcloud users the wrong impression. Using “enterprise ready” to describe alpha-state software and marketing features that never even have existed is just dishonest and it hurts the amazing Nextcloud project overall (see the reviews at apps.nextcloud.com/apps/end_to).

@hehemrin [“4/3”] What’s my suggestion for Nextcloud GmbH? Address the breaking bugs, kill the roadmap, tell the world why the extension didn’t end up as initially marketed and start marketing the extension for what it is: a simple solution to add extra protection for specific files that never have to be shared with anyone. Be upfront with that Nextcloud isn’t going to be an E2EE solution, so that users who need it can look at alternative solutions (e.g., Cryptpad and Cryptomator Hub).

@karlemilnikka I fully agree with your view how Nextcloud should act.

@karlemilnikka Thanks! Hmmm now I'm surprised and confused. I have thought of later self-host Nextcloud, for the moment I have a free account from a provider. Acc to their info, free service is not E2E, server side encrypted. But if I upgrade to paid, they state it is E2E, but maybe not true then. Wonder what other providers state. I have to read more about Nextcloud E2EE (and lack of it)!

@hehemrin Interesting. Do you want me to see if I can find any additional info regarding your provider? If so, let me know which provider you are using, either here or DM me on Signal (0735181000).

Sign in to participate in the conversation
Librem Social

Librem Social is an opt-in public network. Messages are shared under Creative Commons BY-SA 4.0 license terms. Policy.

Stay safe. Please abide by our code of conduct.

(Source code)

image/svg+xml Librem Chat image/svg+xml