UtahFS: Encrypted File Storage
blog.cloudflare.com
blog.cloudflare.com
Mobile is still a problem though. A gallery system would be a big help but you’re always stuck with a bandwidth limit unless you cache the vault locally which for my vault isn’t feasible and also undesirable as I don’t want the files on my device.
> Keep in mind that this system is not used in production at Cloudflare: it’s a proof-of-concept that I built
1. Cryptomator: it's immature and buggy, especially the 1.5 version. See comments in forum.cryptomator. The files and folders disappear, vaults crash, vaults fail to mount, etc.
Boxcryptor is the paid version and not buggy. But it's not open source.
2. EncFS. Has security issues that haven't been resolved.
3. CryFS. Too slow and immature.
4. Encrypted backup, like rclone or duplicity. These are not sync tools.
5. eCryptfs: Used for Ubuntu home encryption (even then somewhat outdated), not for cloud.
6. AWS KMS: server side encryption; amazon has the keys.
7. Gocryptfs: It's OK. Reasonably fast. Cons: command line only, and for Linux. Uses OpenSSL library which isn't all that secure.
It seems to me gocrytfs is the best among these.
Gocryptfs has a comparison of these projets, here [2].
Focused on Windows only, to my experience, securefs is the one that is working the best as it is not using dokany but winfsp (FUSE for Windows). With all other solutions using dokany, the copy or sync of large number of files is damn slow or hanging.
Also it lacks authentication. The snapshots of the XTS mode are prone to certain attacks.
The second one, TIL and good points!
Plus, ORAM provides no protection out of the box for timing based attacks.
Love the crypto fs work you're doing at Cloudflare.
It will be interesting to see how this project does against its competition.
SiriKali[2] is a front end to a majority of these projects and it works on Linux, MACOS and windows.
The main drawbacks are that EncFS will not hide your directory structure and file sizes and also that not all of the EncFS vulnerabilities that were discovered in 2014 have been addressed with an EncFS 2.0 release.
--
² or one of its similar alternatives of course
I haven't looked at native OpenZFS encryption... The method I used for a while was having a Veracrypt volume locally of all my files, and zfs-sending it to a remote location. It is a large file, several gigabytes. However, any updates made locally would get synced remotely at a block level vs. a file level, so the whole encrypted file didn't need synced. Much better than rsync, for example.
I did not read the entire F'in article yet, I just stepped in while a CI/CD pipe was running at work :) BUT! this looks like a pretty accessible article about filesystems.
I also wonder if it is named UtahFS because of the NSA facility near Salt Lake City.
I documented the installer hack at: https://linsomniac.gitlab.io/post/2020-04-09-ubuntu-2004-enc...
Before that I was running my storage server using LUKS on the raw devices and ZFS on top of that, since 2008, and that worked well.
Yeah I wondered this too. They don't say why they chose that wording. Maybe it's a subtle nod to that datacenter
Another thought less well explored would be to swap space with friends such that you hold each others pins but you can't read your friends' encrypted blocks. This is kind of the premise behind filecoin, which lets you buy space (ie if you want someone to hold your blocks) and sell space (ie, mining is equal to holding someone's blocks).
Also, you probably shouldn't trust them even if they did offer this anyway.