incredibly fucked up privacytools.io still recommends nextcloud

@tuxcrafting i just think recommending unencrypted cloud storage on a privacy-focused site is a terrible idea + nextcloud is a buggy piece of shit

@animeirl @tuxcrafting but security and privacy are two different concepts.

@animeirl @tuxcrafting I would argue that unencrypted data I have on an inaccessible storage unit is private.

@xiao @tuxcrafting i would argue that that is only ever arguably the case if said storage is not connected to the internet

@animeirl @tuxcrafting now I have to ask - what part of nextcloud is "unencrypted" in a way that makes a practical difference to privacy?

@xiao @tuxcrafting all your data is stored either unencrypted or encrypted with a server-side key meaning anyone with access to the server can view all your data (vps provider, people in your house if it's a local machine, hackers who gain access to the system in any other way)

@animeirl @tuxcrafting for which hosting project is this not the case? And how do you propose nextcloud to solve the problem?

@xiao @tuxcrafting end to end (client-side) encryption. data is encrypted and decrypted on the local device and only ever stored in the cloud encrypted. encryption keys are only ever stored locally as well (derived from the user's password) The other cloud provider listed on privacytools, S4, makes use of this as well as several other cloud storage providers such as mega, keybase, sync.com and others.

@xiao @tuxcrafting nextcloud actually claims to have end to end encryption on their website: nextcloud.com/endtoend/ but this is "aspirational" (aka a lie). There's an alpha e2e module but it doesn't work and has been abandoned for around a year and hasn't supported the last 2-3 major versions of nextcloud.

Follow

@animeirl @tuxcrafting they do state that it is only in the "testing phase", so I don't think it's fair to say that they promise the feature. It is unfortunate marketing speech that can mislead people, and that is generally unacceptable, but not something that breaks trust in the technology amongst tech people, I think.

Sign in to participate in the conversation
Librem Social

Librem Social is an opt-in public network. Messages are shared under Creative Commons BY-SA 4.0 license terms. Policy.

Stay safe. Please abide by our code of conduct.

(Source code)

image/svg+xml Librem Chat image/svg+xml