Show HN: NoFile.io – A simple file storage site with lots of perks
nofile.io
nofile.io
On the profitability of image hosting websites - https://drewdevault.com/2014/10/10/The-profitability-of-onli...
I suggest you read it. In a nutshell: don't.
The problem is growth. It will quickly get too expensive and you will not have nearly enough revenue to support it. I guarantee you it will happen.
Currently I run a file hosting service with controlled growth. Accounts are not available to the public - you have to apply for one, and I approve them conservatively (130 approved, 137 rejected users as of writing). All users are also expected to donate. I think all new file hosting sites should take link rot seriously and if they don't it's a net negative on the internet. I hate that if I look at a forum post written >5 years ago, odds are all of the images will be broken.
If anyone wants an account on my website, I might be inclined to approve a few today: https://sr.ht
[1]: http://www.techtimes.com/articles/33710/20150220/wetransfer-...
There are tons of pomf.se clones - many that have been going on for years as well. The important part for many of these hosts is that (a) enough people donate to keep it online and/or (b) the community remains small enough to remain affordable for the dev. Personally I use a combination of safe.moe and mixtape.moe.
Often times I've noticed these are "labor of love" projects where a dev can work on learning how to (a) keep a server running and (b) upgrade services without any/significant downtime, etc. Standard DevOps things. The monthly cost to these sort of people is seen as a "learning cost" in a real environment where they have hundreds of, if not thousands or more, users depending on them to not mess things up.
>I hate that if I look at a forum post written >5 years ago, odds are all of the images will be broken.
Inactivity pruning is largely to blame for this, not just new websites going under. IIRC, even Imgur does pruning after 6 months of inactivity (no views) which is totally possible on niche technical forum posts.
Why do you do this ... that is, run a file hosting service for 130 people ? Is it a friends and family IT enabler sort of thing that you do to be nice ?
Or is there some kind of business here that I can't envision ?
The world is a smaller place than it seems. I've noticed this site having a measurable impact on the web around me, and lots of files that might have disappeared are sticking around now (23,946 of them, in fact).
1. contributing your own bandwidth to the images you upload
2. contribute your own bandwidth to the images you look at.
If you look at an image, maybe you should be required to seed it twice over. If you upload your image, maybe you have to seed it at least 10 times for it to stay up past a certain deadline.As a user of image websites and, well, websites in general, I'd gladly contribute my bandwidth to help the services run. Or even act as a mirror rather than a shared peer.
What do you think about that? It could lessen the load on the image host and help scale things. I just can't seen this happening if you embed an image directly unless you embed iframes or require users to go to the site itself.
Right now we're focusing on patching bugs and providing a stable service, but in the future a premium service will be created which targets heavy users.
PS You can change the status of the last active host in your list (Minus.com) to shut down as well.
The primary reason it's still alive today is out of obligation to the URLs (2 million or so) that call it home. If you don't already find this fun and don't feel the same obligation, then you'll join the thousands of others littering the web with 404s.
Also, be aware that people will upload bad shit, and you can look forward to phone calls from the FBI and others.
The site is open source, maybe you'll find it useful: https://github.com/kudos/hostr
Throughout history, we've learned to write down and preserve important stuff. Sometimes we've gotten it wrong or we create huge single points of failure (see, e.g., Library of Alexandria), but we should be careful in assuming that preserving everything is inherently better than the historical approach.
In addition to what's been mentioned, another possibility is to force users to bring their own domains to the table when doing hosting; the user is free to host things from the service at their own domain, and the hoster's domains remain distinct and untainted.
Could be interesting to sell these placements to advertisers: if you don't donate, we'll change all your linked images to image ads after 12 months.
"Hmm, this looks pretty... what is it for?
It has a huge area that says "click here or drag and drop to start uploading"... but uploading what? And why?
Let's scroll down and read the 'about'!: "Fast", "Compatible", "Encryption"... um... ok but WHY?! Is it personal file storage for me (Like Dropbox?) or is it like a public FTP server? Or something else? If I drag and drop my tax return there is it suddenly shared with the entire world? Why do I want this thing?! Back to the HN comments to find out more!"
Something like that anyway! According to the comments it seems to be more like a rapidshare/mega thing - and now that I get it I'll keep this site in mind for sure!
The upload box is the first and almost only thing that you see when you go to the page and the purpose is to make the process simple so that you don't have to click through to a second page in order to start uploading.
You do however have a point as it could be confusing for some new user who haven't uploaded files before. We'll try to add an info box or some additional text to make the message more clear, thanks for pointing it out.
Localhostr was great for a while for just uploading stuff without needing to bother with accounts or RapidShare's wait-a-minute-or-pay thing. It makes sense why you scaled back the free version (I can imagine that these services quickly get expensive to run..) and started requiring accounts. But personally that's the point where it was roughly equally annoying to upload to Hostr and my own server, and so the latter just made more sense for me personally.
var aesCtr = new aesjs.ModeOfOperation.ctr(encryptionKeyBytes, new aesjs.Counter(-1));
Please use https://github.com/bitwiseshiftleft/sjcl which supports a very high-level sjcl.encrypt(passphrase, plaintext) API and has been audited, instead of using crypto primitives.One specific issue is you are only encrypting, not authenticating, so if the servers are compromised someone could send back a fake plaintext.
That's the assumption that file authentication would remove. Well, assuming that the server isn't also sending a backdoored client..
The server is sending the JS responsible for doing the encryption, no? If the server is compromised, all bets are off. You must trust this third party with your (unencrypted) data, unless you verify the JavaScript each and every time.
The reason to why the content isn't being authenticated is due to memory issues in the browser, but we're close to adding a solution for that as well.
Overall the encryption feature is currently in BETA and there will be large amount of improvements before it's finalized.
I don't know if this was intentional on your part, but if so it's pretty deceptive.
I know how difficult affiliate advertising can be, sometimes. Perhaps conventional ads would work better for the site?
Everyone I have shown Oh By[1] to has immediately wondered "Oh, could you upload an image instead of text ?". The answer is no and will always be no, for these reasons.
It's evident right here on HN - limiting people to text weeds out a lot of the children/griefers/criminals.
[1] https://0x.co
Maybe you have something in place to prevent that?
If not - then I can envision an API of sorts that you could feed an image to, chunk it out, get the codes, then do the reverse...
...the thing is, if I can see this possibility - somebody else likely has long before me (I'd hope).
Judging by your username - is there a connection between you and the infamous file hosting site Oron that closed down a few year ago?
Have you considered how much takedown requests you will get if your site becomes popular? It could be hundreds to thousands per day (some ex file hosters ITT could tell how much).
You'll need a whole lot of premium customers to cover the costs of reviewing the takeodowns.
The key is absolutely does not contain enough entropy, because your key material is only comprised of the ascii-printable hex chars converted into a byte value. So instead of a byte having 256 different possibilities, a byte now will only be one of 16 values. Bruteforcing these keys would be incredibly trivial. To decode the hex into actually random key material, you would have needed to do something like hexToBytes("5827800f46cef978"), which would yield a correctly random byte array of [88, 39, 128, 15, 70, 206, 249, 120]. Note that this is half the proper key size required for AES-128.
I also want to echo the concerns already voiced by others in saying that key material needs to be generated from a strong random provider, and not just from the hash of the file.
I say this in the interest of privacy of those who might use your service, so please don't take any offense: please disable the encryption feature entirely until you can get assistance from someone with extensive experience in implementing crypto, because as it exists now, the implementation is fatally flawed.
The About section fits:
FAST - yeah, nothing faster than /dev/null, ok :)
Compatible - sure, why not.
Encryption + Secure - sure, it's hard to get anything out of /dev/null :)
Simple - no kidding...
The first hint that it might actually not be a parody site was the Preview part and then the file size limit in FAQs.
Even the Which file types are accepted? / All of them. combo works great for the /dev/null premise.
Feedback: the navigation bar at the top is quite unusable from an UE point of view. The positions of the icons (and therefore the hovering position) change as the mouse hovers them. It is quite annoying.
Also, in the FAQ: "How can this be a free service? Magic" This sounds to me as: "stfu, don't ask, you are not clever enough to understand" or "there is some dirty way to get money from you, better don't ask".
The main difference is that nearly all of these hosts specialize in a specific type of storage. As an example MEGA forces all users to client-side encrypt files before uploading which is useful for sensitive files, but it comes with the cost of incompatibilities with older browsers and devices which can't decrypt/download the files.
Uploaded provides lots of space for the uploaders, but then pushes all users to its premium plan. The site is ridiculously slow to use as a free user as they cap download speeds to 50 KB/s (they bump it up to a 70 KB/s if you take the time to sign-up).
NoFile bundles all the perks of the different hosts and gives the user more options and fewer limits. You can upload large files and choose whether you want to password protect, encrypt or disable previews for your file while still giving the downloaders speeds of at least 2 MB/s.
It's just a simple file host that allows you to share files without having to worry about the downloaders being infected with a virus, not being able to download
What's your business model?
At the moment there is no revenue source. As costs for the hosting go up, there will be a more "humane" premium plan added in the future, but it will targeted to very frequent users and as a free users you won't be affected by the changes.
How do you want to keep DMCA claims at bay?
If a valid DMCA request is sent in together with a link then we will be forced to respect the content creator and take the link down.
Does this work mobile?
This works on every single device regardless of whether you have Javascript enabled or not. If you however enable the client-side encryption feature (currently in BETA) which is disabled by default then users on older browsers and devices won't be able to download your file.
So what makes you think your fate will be any different than that of all the other free file hosts that have had to resort to advertising in order to survive?
I don't mean to be negative, it's just that I've seen the transition from free to freemium to ad-supported to Rapidshare to dead happen over and over again. These services don't seem to operate with large margins - from the outside, it looks more like all of them are on the brink of bankruptcy.
Lets imagine our average citizen uploads quarter of a gigabyte, that means 4,000 visitors uploading files per $10 client. Assuming you can keep other costs really low, it's not too outrageously expensive.
Rapidshare was a service that had to swiftly and reluctantly change their business model. They were operating out of large offices with over 60 employees and due to the change they saw a sudden drstic drop in revenue.
Rapidshare's financial information isn't public since it's a private company, but one could argue whether they were actually losing money or not making the profits that they expected at the time of the shutdown.
Then came the FBI raid against various filehosts. I remember few of the other hosts got taken down and charged, while others shut their site down as precaution. I remember Rapidshare starting their decline during this phase, something tells me Rapidshare did it on purpose and 'ran away' with the earned money before the feds got them.
Well thats my theory :)
In plain-English, what does this mean?
The most concerning aspect of your model is charging users for download speed. That might cause users to pay you, but it puts an incentive on business to host questionable content. Megaupload and Rapidshare were doing the same thing.
- How active the file is (e.g if the file isn't downloaded in X days).
- How much space that's available on the storage servers.
As mentioned in a previous comment, the site's operating on small margins so the majority of the income will go to expanding the storage in order to make sure that your file is never deleted (unless you request).
At the current rate your file would never be deleted (again, unless you request it) and at a bare minimum your file will be stored for at least a week without downloads so you don't have to worry about your file being deleted before your downloaders get to it.
This will be updated in the FAQ section to avoid confusion as well, thanks for pointing it out.
Edit: also, password protection is enforced server side, and has nothing to do with encryption
The password encryption is indeed server-side, but it is mainly there to protect the file against anyone who somehow finds/guesses the URL and it's a useful feature if you want to slightly increase the level of security without encrypting the file with AES.
That is incorrect. Knowing the hash does not mean you know the contents of the file. You should generate encryption keys randomly, preferably using a secure random method such as that shipped with SJCL, rather than JavaScript's random API.
Random strings and numbers are also securely generated through a CSRPNG with window.crypto.getRandomValues().
Tried to upload a 9.66 GB test file but am getting following error message
"File Size Limit This file is too large. The largest file size that can be uploaded is 1.25 GB"
What am I doing wrong?
It's been changed and you can now upload files up to 10.2 GB, thanks for pointing it out.
Few comments:
Animated backgroud is very distracting. I'm constantly reacting to the new icons floating into the screen.
Underlined "Or" in "Click Here Or Drag & Drop To Start Uploading" makes me think it's some kind of a link. Any reason to underline it?
If I upload multiple files (which worked well) I want to be able to copy all the URLs at once. Displaying them in a text box would be good.
"Animated backgroud is very distracting. I'm constantly reacting to the new icons floating into the screen."
Another user pointed this out and a toggle for the animations will be added to the settings so that you can turn them off.
'Underlined "Or" in "Click Here Or Drag & Drop To Start Uploading" makes me think it's some kind of a link. Any reason to underline it?'
It's underlined just to separate the two options (clicking and dragging) for those who just read the "Click Here" part and assume that the rest of the sentence is just a description to why they should click here (e.g "Click here to start uploading your file").
"If I upload multiple files (which worked well) I want to be able to copy all the URLs at once. Displaying them in a text box would be good."
Instead of a text box there could be checkboxes next to each file allowing you to copy URLs and delete files in bulk. We'll work on adding this as soon as possible, thanks for your suggestion.
This is a very very naive view of the situation. You're allowing user A to upload content which can be downloaded by an infinite(?) number of other users they give the link to. Therefore it will be used for piracy. And worse.
Edit: actually, a free unmonetized file hosting site? In this day and age? Behind whoisguard and cloudflare? Ideal law enforcement honeytrap tbh.
Protect sensitive files with encryption. Only users with the URL will be able to view it. "
This is not encryption - you should change the copy to tell what encryption is used (AES-128 from the info here), even if it's beta. Some more information on that will be welcome.
A link has also been added to that block to make it easier to find, thanks for pointing it out.
"Your file is first securely encrypted using a secret key (AES-128) with Javascript on your device. Once it has been encrypted, the encrypted data is uploaded to a NoFile storage server over a secure HTTPS connection preventing any malicious users from seeing what you're uploading (as an extra layer of security).
Only those with the secret key (which is in the URL) will be able to see the correct content and filename - if a single character of the key varies, then the file will be unrecognizable."
You need to set this as your preferred method on the upload page.
Best of luck anyway, and good luck dealing with law enforcement. Make sure you put some text on the front page indicating that you will collaborate with LE and it might save you from a little bit of bad stuff.
I ran something like this for a couple of years and shut it down because I was tired of dealing with the filth.
CTRL+F finds no other asterisk on the page, what's the caveat?
You should now be able to see your own PDF instead of a placeholder, thanks for pointing it out.
> As long as possible
What a stupid answer to that question! (it gives more info - "You can set an expiry time by pressing the "Options"-button that's next to your uploaded file, otherwise your files will float in the clouds for as long as possible." - but it still doesn't really give any answer)
In all likelihood, the internet itself might evolve into something different in that time. This service might get bought out, or shut down, or the original founders may (fate forbid) get hit by a bus next week.
Setting any sort of indefinite limit is opening themselves up for legal action if it is even one minute less than someone expects. "As long as possible" at least is honest enough to say that as long as there is enough interest to keep the lights on, they will be there.
What makes you think that ? It may be days, where "as long as possible is "we hope to keep the files a few weeks".
Without some sort of project plan you don't know if NoFile.io is aiming at snapchat for file, or S3 for everyday Joe.
The following phrase made me feel a little uncomfortable about using the product.
"How can this be a free service? Magic. In the future a paid service will be introduced offering more awesome features, but don't worry it shouldn't affect the free service."
I'd rephrase this - definitely remove the shouldn't as that tells me that while my files shouldn't be deleted, they might be.
Finally, just a minor thing, but the down arrow under the "Click Here Or Drag & Drop To Start Uploading" doesn't work for me (latest Chrome on Mac). I assume it should scroll down the page but it didn't for me at least.
NoFile is a simple tool that allows you to quickly share files with lots of options, nearly no limitations and at the same time as you don't have to sign in.
"I'd rephrase this - definitely remove the shouldn't as that tells me that while my files shouldn't be deleted, they might be."
You're right about that as the premium plan will never lead to files uploaded by free users to be deleted. The premium plan will only be targeted to more heavy users and won't affect the free users.
"Finally, just a minor thing, but the down arrow under the "Click Here Or Drag & Drop To Start Uploading" doesn't work for me (latest Chrome on Mac). I assume it should scroll down the page but it didn't for me at least."
The button was indeed not working and it's now been fixed, thanks for pointing it out.
put that on the top of your page!
* Title Case Everywhere Looks Weird
* Hovering over 'resolution' on the detail page shows a tooltip with the text 'Upload date'
* I uploaded a .NEF file and it seems to think it's 160x120 (it's actually 6000x4000)
* The buttons next to the link field on the detail page are not the same height as the input.
* When uploading the background icons become jerky (presumably due to the upload causing long frames)
* When uploading there was no speed / ETA data shown, just a spinner.
* I felt the animations on the homepage were all a little superfluous.
* The links in the footer link to places on the page, but without updating the URL hash, probably worth adding one to make it more linkable.Also tonnes of decent ad supported options with no crap like wait time and million popups like Openload Zippyshare AFH
(oh and site looks & performs great! Best of luck for future)
Did you mean to infer that MediaFire was less crappy than this showcased one? Or crappier than this one? Your follow up sentence would indicate the latter.
OP's site looks great!
The problem being that you have to jump between different hosts depending on how large your files are and which features that you want to use (e.g Mediafire for larger files, Zippyshare from public PCs so you don't have to login, MEGA for sensitive files that you want to send securely, Dropbox when you don't want grandma's PC to get infected when you're sending her the videos from Christmas).
The goal is to create one single host that saves you from having to jump from each host and having to maintain dozens of accounts to bypass limits.
My first thought was that it would be fantastic in a case where I needed to pull a file off a server I was SSHd into but didn't feel like setting up a SFTP session. Of course, in that case I probably wouldn't be comfortable having the data pass through a third-party.
Question - would you, in the future allow uploading to configurable destinations, e.g. my own S3 buckets? Also, do you track the number of time a file asset was downloaded from your service so that the original uploader can check activity stats?
EDIT: Feedback - when I scrolled to the bottom of the home page, the "There is something I have to tell you" section is duplicated under itself.
Right now there's only an option to upload files to Dropbox, but the plan is to add as many useful alternatives as possible and S3 would be a good option.
The number of times a file was downloaded is currently being counted, but it isn't public. It would be an interesting idea to display it on every download page by default (similar to Imgur) and give the uploader the option of disabling it.
The duplicated info block has also been replaced, thanks for pointing it out.
curl -o /dev/null -v https://nofile.io/f/01ZAJO7Qhfe
* Trying 104.18.59.89...
* Connected to nofile.io (104.18.59.89) port 443 (#0)
* TLS 1.2 connection using TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
* Server certificate: sni212289.cloudflaressl.com
* Server certificate: COMODO ECC Domain Validation Secure Server CA 2
* Server certificate: COMODO ECC Certification Authority
* Server certificate: AddTrust External CA Root
> GET /f/01ZAJO7Qhfe HTTP/1.1
> Host: nofile.io
> User-Agent: curl/7.43.0
> Accept: */*
>
< HTTP/1.1 200 OK
< Date: Tue, 07 Mar 2017 15:18:16 GMT
< Content-Type: text/html; charset=UTF-8
< Transfer-Encoding: chunked
< Connection: keep-alive
< Set-Cookie: __cfduid=d3f6984a870cdd03cea954585ac19e38c1488899895; expires=Wed, 07-Mar-18 15:18:15 GMT; path=/; domain=.nofile.io; HttpOnly
< Vary: Accept-Encoding
< Strict-Transport-Security: max-age=15768000
< Server: cloudflare-nginx
<
{ [957 bytes data]
* Connection #0 to host nofile.io left intact
Looks like that ran through Cloudflare, even if it wasn't cached. Doesn't look like it's going directly to whatever storage you are using.All those useful features have been added to NoFile and made available for anyone who wants to use it - all free from ads, registrations, payments and it respects your privacy. Here are some of the current features (more to come):
* Simple upload process compatible with nearly all devices - accepts files as large as 10 GB to be uploaded
* Upload & download files without Javascript enabled (nearly all features are still available, although the site runs smoother with Javascript enabled)
* Password protect files (hashed with SHA256)
* Ability to encrypt files with AES-128 on the client-side before uploading to the server for secure storage (BETA)
* Easily view the metadata of a file (file type, dimensions, upload date, size, etc.) on its download page (URL to a live demo below)
* Preview files (PDF viewer, video/image/audio previews) before downloading (see demo URL below)
* All transfers are made securely over HTTPS to prevent malicious users from viewing what you're downloading/uploading (forced SSL)
* Securely view your upload history without having to create an account (history is stored in your browser's local storage)
* Save files directly to Dropbox (Dropbox scripts are only loaded when button is pressed to protect your privacy)
* No tracking codes and no third-party CDNs are used for external scripts, CSS or fonts in order to protect your privacy
---
Here are a few demos
- Download pages
https://nofile.io/f/BJ6MyXboYLj (an image with its preview enabled)
https://nofile.io/f/UH58eLI68Cl (an image with its preview disabled by the uploader)
https://nofile.io/f/Yl4NcFvsliN (an image with password protection - password is 12345)
https://nofile.io/f/OoG2wQwS33R#c725690e45b3a393 (an image encrypted with AES-128, secret key is stored securely after the '#' and not transmitted over the HTTP protocol)
- Upload completed page
https://nofile.io/edit/?id=UH58eLI68Cl&key=w69gz2D5y0RoH9umu...
To start uploading your own file(s) within seconds (without signing up): https://nofile.io If you have suggestions, a complaint or any features that you would like to see added then feel free to leave a comment or use this contact form: https://nofile.io/contact/"
Imho, if you really want to be the "Google of file-sharing", then the UI should be a lot less distracting.
Perhaps it would be useful to add an option that toggles the animations on/off.
If hundreds of people are telling you the animations are too much, kill the animations.
If a small handful of people are saying it, ignore them.
But please, please, do not add _any_ complexity to a small-margin, intentionally simple service like this in the hopes of pleasing everybody.
When you upload the same file it warn. Good enough. But when you continue anyway the KB/s and ETA displays do not show anything.
How can I view my history? I think I've clicked every link available but I can't find this at all.
I do see some data in my localstorage. I'm not expected to fish it out myself from there am i..?
> You can set an expiry time by pressing the "Options"-button that's next to your uploaded file
Same for this. There is no such option to be found. Screenshot: https://www.NoFile.io/f/FHA0M03bmm0#057e7d69b089e719
Also, I tried downloading my own screenshot but nothing actually happens. (The loader does pop up) Downloading & preview does work for an unencrypted file.
Firefox 51.0.1 (64-bit)
The button had been hidden for some users due to a bug. It's been fixed and you will be able to see it after refreshing the page, thanks for pointing it out.
"Same for this. There is no such option to be found."
This feature was disabled shortly after the launch due to a bug. It'll be added again as soon as possible.
Without some sort of guarantee of availability, I wouldn't be able to recommend it to friends, coworkers, or family. I don't want to advertise something that is truly a great service but ends up shutting down few months from now after people start abusing it.
But if the site does decide to shut down then we will be sure to notify users about this at least a month in advance in order to have time to make backups.
Console gets spammed with "not active or paused - skipping speed" messages, what are these?
There seems to be an onclose-like handler which warns me that I might have not saved the changes (I've uploaded 6 files). Do I need to "save" somehow? I see no "Save" button, nothing similar.
The warning message that you receive when trying to close the page is only there to prevent accidental exits and in case you're in the middle of an upload or if you haven't copied the URLs of the uploaded files.
Unfortunately browsers no longer allow you to change the warning message, hence why it's telling you to save.
I'd like to challenge you on the site name, though. Why'd you pick it? If I'm a normal user who stumbled across the site, I might be confused if a site called "NoFile" wanted me to upload files.
Testing on FF 51.0.1 and I can't seem to see the expiry option which is supposed to be alongside the file that I uploaded. Maybe using a different browser would work?
As mentioned in a previous comment, since uploaders aren't rewarded for downloads this shouldn't become too big of an issue to handle.
All requests will be checked and the file will be taken down if the request is valid.
> All of them
It is not accepting my Calculator.app. It just sits there, never uploading.
This issue must've been caused by something else. Were you able to upload other files?
Is there any other options other than dropbox?
You can upload as many files as you wish and save them on your phone to play offline (similar to what an app would do in the background) or play them directly from the site.
Although most operating systems don't allow users to upload files containing greater-than/less-than symbols, it's possible to add them by tampering the requests and changing the filename.
From there you could change the filename to "<script>alert("xss")</script>" and run an XSS. This has now been patched by encoding the characters.
Once we're a bit more stable we'll be sure to release a bug bounty program.