Airborn: Create and edit files online, securely
airborn.io
airborn.io
The initial assumption with these types of services is always that an attacker, having compromised their servers, could simply inject malicious code into the browser.
From their docs:
> Normally, when hackers get access to your server, they can change the code that gets sent to customers. For example, they could make the code say "send your password to us". Then, even though they can't read documents immediately, passwords start coming in and they can soon read them.
> To solve this, we're using a relatively new web technology (Service Workers) to install some code which can't be changed without setting off a warning to you. That code then keeps taps on all other code, and checks that it matches the publicly available version on GitHub.
Interested to see how robust it is...
But how would you know an app developer wasn't compromised and signed the next version with a backdoor also?
And I think it's a genius use-case for Service Workers. From their security page[0]: "we're using a relatively new web technology (Service Workers) to install some code which can't be changed without setting off a warning to you. That code then keeps taps[sic] on all other code, and checks that it matches the publicly available version on GitHub."
Combine this with HSTS, and you can be certain the code running hasn't been modified by a third-party.
To be precise: If it works as described, it makes it (a little? substantially? orders of magnitude?) more difficult for third parties to modify the code.
"Certain" is not a word used in security, IME.
That section attempts to explain how web apps work today, if you don't use that library. Reading the entire thing back, I agree that the how is never explained very well, although https://www.airborn.io/docs/security does explain it.
I'd recon they would suggest you keep 2 tiers and add a call us tier for b2b enterprise.
I see where decently sized companies would pay a lot more than $10/month/user to ensure their sensitive docs can't be stolen.
I certainly am no expert but if the product works as it seems this should be more valuable than $100/year/employee.
Always happy to help where I can when it comes to pricing.
PC
He’s going to roast your pricing but I’m sure you’ll grow a ton from it.
Seems like Patrick is in this thread, so sorry if I’m off-base, but I really would like to know what I did to deserve hundreds of emails from “Patrick at Price Intelligently,” because I’m pretty sure I never subscribed to his list.
(It’s not just him, btw - the worst are the GitHub profile scrapers that somehow manage to make it into my “primary” inbox)
Ironically, could you email me the email address to patrick[at]priceintelligently[dot]com and I'll investigate. If it slipped in or you ended up actually opting in, definitely will take it out. If it's a larger issue, definitely will solve it. Obviously, apologies either way.
(Porting contacts between lists seems dangerous btw. IANAL but pretty sure subscribing to one list does not count as opting-in to another.)
On that front we automatically just don't touch any of the unsubs for the new system, so was worried that was messed up. Doesn't look like it though. Not a lawyer either, but from my understanding it's the same list even if you change marketing automation/email products. GDPR is making this fun, too. :)
"Airborn: Create and edit files online, securely."
HN has too many submissions with single-word headlines that tell you absolutely nothing about what you're clicking on.
If Airborn creators on on this thread: how did you think about getting people to pay while making the source available? It doesn't seem commonly done.
We're basically banking on medium-size businesses finding it more convenient to use a hosted service, especially when it offers the same or a higher level of security.
- here [0] "All documents are encrypted before they leave your computer" how then one can collaborate as in gdocs (from the pic it seems like that)
- what key do you use for encrypting the docs? is it the user password? if so it can't be recoverd (as dashlane for example [1]) is this the approach?
PS: the login seems broken https://www.airborn.io/app
[0]https://www.airborn.io/docs/security [1]https://support.dashlane.com/hc/en-us/articles/115003111325
- When you sign up, the page downloads a file on your PC which contains your username, and your password encrypted with a "password recovery key". When you lose your password, we send you your password recovery key and you can decrypt your password with it.
Login being broken is weird, do you see any errors?
Having the password recovery keys, can you decrypt user passwords? Does that matter in this scenario?
Is this security not already standard, and not practiced by companies like Dropbox? As a side note, I like the collaboration aspect and one-person-per-paragraph is a pretty smart idea!
Edit: To those downvoting, sorry, I'm just curious and I think some of us were unaware of the differences between Airborn and other services, which I've now learned can still view your data
1. https://www.kalzumeus.com/2012/08/13/doubling-saas-revenue/
Is anyone else seeing this? It needs a bit more polish before I could use it for encrypted collaborative editing.
I’m more interested in how you handle the encryption keys. Specifically, how does a user share a document with another? You mentioned that the “share group” has its own private key; where is this stored?
It’s pretty clever, I like it. Definitely not the holy grail of client side browser-based multiparty encryption, but you’ve found some innovative techniques. Bravo, good luck with it.
Is that a change in focus or a limitation of the demo?
Under the hood, it's theoretically still super easy to add/install apps in Airborn, though, and Firefox OS's marketplace server is open source, so maybe in the future?
Performance seems really smooth, I'm glad to see this is still coming along quite nicely.
Even if it isn't the best UI, I think you really do still need to get something like EtherCalc on here, even for personal use, I love spreadsheets for storing structured information, and for business users, it's almost definitely a need.
Also, is there a reason you're using inline styles to do italics and bold instead of the specific tags for those things?
(Deleted question you answered downthread.)
Regarding inline styles, I don't remember why, sorry. It might again have been to fix some inconsistency between browsers.
Unless e.g. they make the system serve up malicious javascript.
Whether that's important to you, only you can judge.