Show HN: YouTransfer – Self-hosted file sharing
youtransfer.io
youtransfer.io
Created to be installed behind the firewall on private servers, YouTransfer aims to empower organisations and individuals that wish to combine ease-to-use file transfer tooling with security and control.
You can watch a live demo at http://demo.youtransfer.io
If you want to see it in action on your own environment, you can use the Docker image (https://hub.docker.com/r/remie/youtransfer/) or NPM package (https://www.npmjs.com/package/youtransfer)
Edit: Sorry, just saw the Demo wiki page now. But a link on the homepage wouldn't hurt as it's what most people would want to see.
If you're familiar with that project, could you comment on the main differences in YouTransfer?
YouTransfer is basically a very simple hit & run file sharing application. The goal is to make uploading & sharing files a matter of 2-3 clicks. The files will be stored with a configurable retention time and will be deleted from the server after they expire.
YouTransfer it's not meant to help you organise your digital life, or have access to all your files remotely. It will only help you share files in a more convenient way compared to SFTP or email.
file.id = md5(file.name + (Math.random() * 1000));
First of all please do not use MD5 for anything anymore, it has known collisions. But you shouldn't also use any hash functions here at all: just generate a long enough random token. Math.random is not a secure PRNG, use crypto.randomBytes in Node or window.crypto.getRandomValues in browsers.PS And multiplication by 1000... is it just for fun?
With the possible exception of demonstrating brokenness in hashing algorithms ;) (Sorry, couldn't resist!)
Actually, HMAC-MD5 is secure.
Yes, there aren't any known attacks right now, but since MD5 itself already has practical collision attacks against it, there isn't any good reason to use HMAC-MD5 in a new cryptosystem when there are better alternatives.
---
Supporting evidence: new versions of OpenSSHD do not use HMAC-MD5 by default anymore: it has to be enabled manually.
The default is:
umac-64-etm@openssh.com,umac-128-etm@openssh.com,
hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,
umac-64@openssh.com,umac-128@openssh.com,
hmac-sha2-256,hmac-sha2-512
http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man5/...Replace with:
- BLAKE2 if you need a fast cryptographic hash function (e.g. for hashing file contents)
- SHA512 (or SHA256, or SHA-3) if you want a standard cryptographic hash function that is available in your programming language libraries
(Speaking of Gravatar, their use of md5(email) or even more secure hash function won't help protect email addresses against dedicated attackers, as it's easy to iterate over billions of them in seconds, just like in the stories about password cracking you hear, but it works as a simple anti-spam measure.)
I would rather have less ad tracking pixels on someone elses websites if possible, but I am genuinely interested in the value that gravatar provides to people who like the service.
But the recommended way is to prefetch the avatars directly from your server and offer them on your own cdn.
As for the value it provides, well for one thing I pretty much never have to upload my avatar to websites anymore - it's an avatar attached to my email addresses instead and that's very nice. Of course I'd prefer a proper identity protocol but nobody's working on one. If you want to, be my guest...
I would rather external actors (say gravatar does nothing wrong) not be able to identify which email address I use on a site they do not own, and not be able to track my user signups by something that might be public information, which generally a site does not advertise.
It just feels wrong.
This doesn't seem like a "create an issue on github" problem though. Surely it is a push a patch today problem?
EDIT: The 1.0.2 hotfix is now available with the token generation fix as well as 2 other enhancements.
Basically forcing him to put up a patch for an unimportant issue on the same day with your entitled comment was a really crappy thing to do.
EDIT: I'm using `crypto.randomBytes(16).toString('hex')` to be precise
Edit: yep, 16 bytes.
6. Security Considerations
Do not assume that UUIDs are hard to guess; they should not be used as security capabilities (identifiers whose mere possession grants access), for example. A predictable random number source will exacerbate the situation.
Do not assume that it is easy to determine if a UUID has been slightly transposed in order to redirect a reference to another object. Humans do not have the ability to easily check the integrity of a UUID by simply glancing at it.
Distributed applications generating UUIDs at a variety of hosts must be willing to rely on the random number source at all hosts. If this is not feasible, the namespace variant should be used.
https://github.com/warner/magic-wormhole
It's file sending from 1995.
0b692a00635682fabc78b6a50655242c.binary gets stored, for example in "./uploads/0b/69/2a/0b692a00635682fabc78b6a50655242c.binary" etc. Too many files in one dir can have problems or be slow.
BTW: normally the files will expire within a specific timeframe and will be removed by a scheduled cleanup process. This should limit the impact, but if the system is heavily used it might become a problem.
[1] XSS Example: http://demo.youtransfer.io/download/%3Cscript%3Ealert(%27xss...
I've created two issues on GitHub (https://github.com/remie/YouTransfer/issues/107, https://github.com/remie/YouTransfer/issues/108) which will be fixed in a new hotfix release asap.
https://github.com/SirCmpwn/sr.ht
pomf.se was my replacement after my own hosting service, MediaCrush, went down.
Much appreciated, added to my list o' useful things.
https://github.com/skx/web-file-publisher
But then as an experiment I wrote another which uses TOTP to authenticate uploads, so you can upload a file directly via CURL with a suitable TOTP device. This is written in golang:
https://github.com/skx/go-experiments/tree/master/publishr
Using TOTP limits compromise if your upload is sniffed, although I run it behind SSL so I'm protected against that regardless.
Interesting project though; and I like that you can deploy it via Docker.
Also, when people run this at home on their home computers there is limited upload speed (typically 1/10th of the download speed).
You could opt for the S3 storage provider, which will dump the files to Amazon AWS instead.
The YouTransfer project does not implement access control or SSL, so it is highly recommended that you look at the hosting options on the Wiki (https://github.com/remie/YouTransfer/wiki/hosting).
I'm afraid there is not much the project can do concerning upload speeds of individual connections at home :)
The speeds issue can be solved by running on a cheap DO droplet or scaleway arm server btw (my city luckily has fiber everywhere :)).
I'm having a little trouble, too. Even making the type a little bit darker would help.
The success of services like WeTransfer or Dropbox is that it is dead simple to use. It does one thing (sharing files) and makes this as easy as possible.
Seafile seems to be easy enough, yet still has a multitude of features compared to YouTransfer. OwnCloud simply has a whole different goal. It's not about sharing files, it is about organising your entire cloud presence (with e-mail, calendar, foto's, etc).
With YouTransfer, you can have the same ease-of-use but on your own terms. It runs on your own servers, with your own (secure) storage. You are in full control.
Given that it is also published as an NPM package, YouTransfer can be modified to suit your specific needs. This makes it interesting for companies to rebrand it and use it as their file-sharing system.
Using the default settings, you would get something like "./uploads/0b692a00635682fabc78b6a50655242c.binary" in the application directory.
I've already has plans on making it possible to change the interface, for instance not allowing direct download from the homepage. I could ament this with the feature to send email notifications to the system administrator upon successful file transfer. The combination of both would allow you to use YouTransfer.io as a public drop box for files. Does this sound about right to you?
How many sysadmins does it take to screw this in?
However, it is highly recommended to either use Docker, a reverse proxy, any of the PaaS providers or a combination of the above.
EDIT: I've updated the wiki with additional information on running it locally.
@namespace url(http://www.w3.org/1999/xhtml);
@-moz-document domain("www.youtransfer.io") {
body{
color:#000000;
font-size: 18px;
}
}How about Proxima Nova? (http://www.marksimonson.com/fonts/view/proxima-nova)