Croc: Easily and securely send things from one computer to another
github.com
github.com
https://github.com/psanford/wormhole-william/releases
I believe croc has some features wormhole doesn't (and some anti-features, like being able to pick curves and hashes). But also just that it's worth knowing that Magic Wormhole is kind of the "default" tool that does this.
Which looking at your link I guess is unrelated
(BitTorrent/Resilio sync uses SSL and seems fine for 1-1 design-wise)
"magic-wormhole has most everything (currently its missing capabilities for multiple file transfers and file resuming), but it requires installing lots of the Python ecosystem which is tricky for non-developers (and Windows users)."
For the python part, I guess wormhole-williams works too then.
AFAIK, croc is the only CLI file-transfer tool does all of the following:
- allows any two computers to transfer data (using a relay)
- provides end-to-end encryption (using PAKE)
- enables easy cross-platform transfers (Windows, Linux, Mac)
- allows multiple file transfers
- allows resuming transfers that are interrupted
- does not require a server or port forwarding
* Allows any two computers, NAT'd or otherwise, to transfer data
* Invented the PAKE model that croc uses
* Is cross-platform and runs on Windows
* Allows multiple file transfers (directories)
* Does not require a server or port forwarding.
The thing croc does on this list that Magic Wormhole doesn't is resumption.
I’m probably missing something, new to magic wormhole, but this seems to contradict the docs on magic wormholes linked by the tool you recommended, wormhole william:
“ The wormhole library requires a “Mailbox Server” (also known as the “Rendezvous Server”): a simple WebSocket-based relay that delivers messages from one client to another. This allows the wormhole codes to omit IP addresses and port numbers.“
https://magic-wormhole.readthedocs.io/en/latest/welcome.html...
Is this a particular library choice vs protocol choice? Wormhole william perhaps allows codes with ip addresses etc?
What makes me wary about these tools is the way many of them seem to bake in a default relay server but aren’t up front about it (i want that discussed in the readme.md, it’s a big deal, even if they can’t read the payload - presumably they can see which two IPs are communicating which should be absolutely disclosed). Like, to me it’s not “magic” to route stuff through a relay server. That’s the whole thing I want “magic” to avoid. (Also it doesn’t seem at all like a “wormhole” - the nomenclature strikes me as insanely grandiose)
What's magic-seeming about them is that you can be deep in a prod network, with tightly controlled ACLs and no routable address, and just "wormhole server.log", and then on your dev laptop on your random home wireless type, like, "wormhole receive 32-hazardous-baboon" and poof! you have "server.log". It feels pretty magical, which is why it has the name.
Croc doesn't change any of that. What croc does differently from Wormhole is that it handles resumption, and you can apparently send a globbed list of files rather than just a file or a directory. Resumption is a real feature (I'd like to know more about how the cryptography works, though). The multi-file thing is a UX tweak.
Croc has a bunch of knobs to change cryptography primitives. Those are anti-features.
You can password-authenticate a custom croc relay. I don't know why you'd ever care. Maybe this is an abuse concern? These are all E2EE designs. You don't trust the server in the first place. It's like a STUN/TURN server.
Nit: Magic Wormhole pioneered SPAKE2's application in a file transfer utility, but the actual invention of SPAKE2 predates Magic Wormhole.
The output of the command tells you what to do next.
They really nailed the UX on this.
The cost of croc is mostly bandwidth - over 8 terabytes of data is sent every month through croc! That's amazing to me since I started this project just as a way for me to share files with friends. Four years ago, the public relay server only costed $5/month, but now it is costing me $40-50/month. The higher cost is enabling file transfers for thousands of people all around the world.
When connection is possible, is my understanding that croc connects directly
The challenges with Croc here are largely the same, but with data as the media instead of voice or video. (Although, “VoIP” can also handle data in this way. See WebRTC data channels.)
I suppose you could try that, and fall back on full data relaying when it doesn't work. Should save a lot of bandwidth.
Of course, that might be a lot of work to implement, not saying it's easy!
1. Try various techniques that might trick the firewalls on both ends to let the connection through. This requires a relay for the initial negotiation only.
2. If (1) fails, then use a relay for everything.
More generally, it feels like in 2023 that connecting two computers via a public relay ought to be a solved problem, on the level of, like, DNS. Or maybe it is and I haven't heard?
// DEFAULT_RELAY is the default relay used (can be set using --relay)
var (
DEFAULT_RELAY = "croc.schollz.com"
DEFAULT_RELAY6 = "croc6.schollz.com"
DEFAULT_PORT = "9009"
DEFAULT_PASSPHRASE = "pass123"
INTERNAL_DNS = false
)
[1]: https://github.com/schollz/croc/blob/f91c7a9948f94007d6be2b0...In principle IPv6 should've solved this problem a long time ago... without a need for third parties.
"toss cleverly encodes port information in the code phrase, making it simple but it requires using connected computers (no firewalls) and the long random-ish code phrase is hard to “tell” someone. magic-wormhole has most everything (currently its missing capabilities for multiple file transfers and file resuming), but it requires installing lots of the python ecosystem which is tricky for non-developers (and windows users)."
> The upstream author doesn't have enough resources to address them on its own and wants to develop fixes in the open. Therefore I have created GitHub issues in the upstream project and publish the full report today.
I.e. the "and wants to develop fixes in the open" part left me with a very different interpretation from when I first read your comment.
https://redrocket.club/posts/croc/
But audits finding vulnerabilities are better than no audit and no known flaw.
Do these tools have iOS apps?
https://nvd.nist.gov/vuln/detail/CVE-2023-43616
https://nvd.nist.gov/vuln/detail/CVE-2023-43617
https://nvd.nist.gov/vuln/detail/CVE-2023-43618
https://nvd.nist.gov/vuln/detail/CVE-2023-43619
https://nvd.nist.gov/vuln/detail/CVE-2023-43620
https://nvd.nist.gov/vuln/detail/CVE-2023-43621
I will stick with wormhole-william, thank you very much.
I use wormhole-william, the Go version of the Python magic wormhole, and age, mostly because of this Latacora endorsement:
Like rsync, it only sends the chunks of the file that changed, so it can be extremely fast for small changes in large files. It's able to use a variety of methods to connect including good through relay servers if the machines can't directly talk to each other.
For systems connected only by a network: maybe I don't see the advantages of these tools (which I have to install first on any client) as all systems I use already provide ssh and rsync to do secure file transfers. Even my Android devices are capable of using ssh/sshd and rsync via the Termux app, so to transfer files between them and a Linux or Mac laptop is easy.
OK, one user has to be proficient in enabling ssh/sshd if needed, but to install software such as the one discussed here, that's no difference.
A useful utility that a friend wrote is https://github.com/akovacs/uploadserver - it's basically a nicer version of:
python -m http.server 8000
Download prebuilt binaries for Linux, Windows, Mac OS from https://github.com/akovacs/uploadserver/releases/
or install from source if you prefer [1]Start the file server, and then navigate to it using the web browser of your choice on any device (no need for a client application).
chmod +x upload_server
./upload_server
Navigate to the server's ip address port 8000 in the browser of your choice and upload files using the web UI or directly via curl: curl -X POST --data-binary @file_to_upload.txt http://192.168.1.X:8000/uploaded_file.txt
Then download the file to another machine or mobile device either from your web browser or via a commandline tool: curl http://192.168.1.X:8000/uploads/uploaded_file.txt --output downloaded_file.txt
[1] Steps for installing from source code: # install rust toolchain
sudo apt install rustc git
curl https://sh.rustup.rs -sSf | sh
rustup install nightly
rustup default nightly
git clone https://github.com/akovacs/uploadserver
cd uploadserver
cargo run --releaseSetup: 1) install an app 2) create a folder 3) share secret link with other systems
Use: 1) open an app 2) see all files in that folder autosynced with another system (if it's also running an app)
So transfer is as easy as opening an app and copying files to a shared folder
It’s then relying on the rest of the IPFS network to propagate the record for discovering the sender and receiver.
- Move "Motivation", "Project Status", "How Does It Work?" somewhere else
- Add "What is It?" and "Encryption" sections and place them just before the "Usage" section. Keep them reasonable small, the smaller the better
I believe that it will help the project to have a much better resonance with the target audience.When sharing files between devices I own (including my mobile phones) I attach them to a draft email to myself, then get them from the drafts on the other device.
A friend wrote a faster and more sophisticated version of `python -m http.server 8000` in rust which also supports uploads, you can read about here: https://news.ycombinator.com/item?id=37628347 File transfers are over the local network, and therefore should be very fast.
python -m http.server 8000
to share a directory over a local network. Then you can point a web browser on another device to port 8000 of the server's IP address to download files. However, this can be slow for larger files.A friend wrote a faster and more sophisticated version of `python -m http.server 8000` in rust which also supports uploads, you can read about here: https://news.ycombinator.com/item?id=37628347
Sorry, I have spoke too soon. I see now it uses a public relay by default, and you can self host as needed. Sorry for the unnecessary comment!
Could probably be a Python script.
You'd have thought by 2023 this would have been solved but I don't believe it has. Particularly as PGP email administration (including key management over time / replacement hardware) is non trivial and unlikely to be successfully achieved by the non tech savvy.
Specifically if cloud services are banned by the solicitor's company.
You'd have thought by 2023 this would have been solved but I don't believe it has. Particularly as PGP email administration (including key management over time / replacement hardware) is non trivial and unlikely to be successfully achieved by the non tech savvy.
Specifically if cloud services are banned by the solicitor's company.
You'd have thought by 2023 this would have been solved but I don't believe it has. Particularly as PGP email administration (including key management over time / replacement hardware) is non trivial and unlikely to be successfully achieved by the non tech savvy.
This works via WebRTC, and since the wtrc package for node.js is not well maintained, the CLI for drop.lol has been abandoned. Therefore croc solves a huge problem that I can't solve in drop.lol right now.
For anyone who needs a web application, this should work though.
(Although: I've stumbled upon a really good implementation of WebRTC in pure Rust, so I might end up trying to get it working with that or even trying to port that to node.js somehow)
How do people transfer their confidential information to say, their solicitors, who may be on different operating systems and behind NAT / firewalls?
Specifically if cloud services are banned by the solicitor's company.
You'd have thought by 2023 this would have been solved but I don't believe it has. Particularly as PGP email administration (including key management over time / replacement hardware) is non trivial and unlikely to be successfully achieved by the non tech savvy.
Then the server tries to make your and the receiver clients connect directly to each other, if this doesn't work (mostly because of firewalls) it also Relais the parts of the file, which by the way are encrypted so that only your receiver client can decrypt
That's my understanding of how it works
Did you transfer a very large file?
Any tool that wants to reliably connect two clients P2P is going to need something like a TURN server to traverse restrictive NATs. See for instance Tailscale's use of DERP servers: https://tailscale.com/blog/how-tailscale-works/#encrypted-tc...
I wish magicwormhole or croc came with every major OS preinstalled.
I'm not aware of any other major OS ;)
Google Drive and Dropbox are both awful mobile clients.
Also you can connect a USB cable.
There should be a way to just right click and "send to phone"
A friend wrote a faster and more sophisticated version of `python -m http.server 8000` in rust which also supports uploads, you can read about here: https://news.ycombinator.com/item?id=37628347
File transfers are performed over the local network, and therefore should be very fast. If you don't have a network connection, you can just enable a Wifi hotspot on your mobile device and transfer the files over that. There is no need to install any software on the mobile device, you can just use a web browser to browse to a directory that you share over the network.
[1]: https://github.com/psanford/wormhole-william-mobile
†: There's also a working iOS port but its not released on the App Store because of how hostile Apple makes that process to open source developers.
For copying the same things on a regular basis, I run rsync scripts in Termux (https://termux.dev/en/). They push photos from my phone to my computer and pull essential backup from my computer to my phone. They also synchronize themselves and Termux configuration. For exchanging files without a direct network connection, I have croc and the Rust version of Magic Wormhole (https://github.com/magic-wormhole/magic-wormhole.rs) installed in Termux.
It may seem arcane and archaic, but I have found this setup better (more predictable and more reliable) than anything "mobile-native". I appreciate that Termux behaves mostly like other Linux machines.
I had a pretty positive experience with Syncthing for Android on my previous phone. It was before I started using Termux. I had a directory called "clipboard" that synchronized between my desktop, laptop, and phone. Sometimes it took a while to notice new files. I would use it if I didn't use Termux or if I needed to keep multiple mobile devices in sync.
If I had to often send files to a mix of Android and iOS devices on the same local network, I would try LocalSend (https://localsend.org/).
It can be or it can be encrypted. FTPS(i|e) implements encryption over FTP. I prefer SFTP as it just uses one port which I can define. SFTP also works better through firewalls and NATs.
VSFTPD is an example of an FTP server that supports encryption or FTPS.
[1]: I am building a UX-focused app over at payload.app, but there are many others, both CLI and GUI/web apps.
``` > traceroute news.ycombinator.com ```
On my computer, most packets take a route that passes through 10+ computers.
I think its not a solved problem to consistently be able to patch two computers on the internet directly.
EDIT: At the moment it is 100% green on VirusTotal.
https://www.virustotal.com/gui/file/a2c3b38bdd8d93bfd40925e1...