OwnCloud 4.0 just released
owncloud.org
owncloud.org
ownCloud began at a KDE community event in 2010, aiming to bring greater flexibility, access and security to data in the cloud. ownCloud enables universal access to files through the widely implemented WebDAV standard, providing a platform to easily view and sync contacts, calendars and bookmarks across devices while supporting sharing, viewing and editing via the web interface. Installation has minimal server requirements, doesn’t need special permissions and is quick. ownCloud is extendable via a simple, powerful API for applications.
With more than 450,000 users, ownCloud offers the ease-of-use of Dropbox with more flexibility and security. ownCloud users can run their own file sync and share services on their own hardware and storage, use popular public hosting and storage offerings, or both.
Other major improvements:
- Drag & Drop File Uploading – Enables end users to upload a file from a browser without installing a client. Simply open a browser, log in and then drag from the desktop into the ownCloud window.
- Shared Calendars and Calendar categories – End users can sync their own calendar, but also share their calendar with others, enabling them to see and schedule appointments while looking at the user’s schedule.
- File Encryption – new server side encryption increases file security while at rest – not even server admins can look at these encrypted files while they reside on the server.
- ownCloud 4 also adds a to-do syncing plug-in, improved contacts and groups, improved file sharing, enhanced the photo gallery, improved system performance, easier installation of third party plug-ins and more. Complete details can be found http://owncloud.org/features.
...if it would only sync FBReader bookmarks and FireFox tabs/bookmarks á la read it later across devices...
You need a simple statement of what the project actually achieves for me, not random promises of "versioning" or pictures of calendars. I've no idea why I need them.
Rob Walling's "Promise to verb your noun" is a great way to quickly get something up.
Edit: Just read about it on Wikipedia. Now I get it.
passwords stored in the clear in server-side sessions => server hack compromises data. storing keys server-side means admins can get into your data.
had a big lol at the use of blowfish ECB - use of any cipher's ECB mode for bulk encryption is asking for problems. they should be using CBC, CTR, LRW or, ideally, XTS modes.
OwnCloud is using Mersenne Twister (not secure) seeded by time of day and PID (which is not nearly enough entropy) to generate keys. The encryption is done in ECB mode, which leaks data (https://en.wikipedia.org/wiki/Block_cipher_modes_of_operatio...). The encryption key is stored in the clear in session data, which usually resides in /tmp.
There's more, but those seem to be the worst parts.
Also, what's the benefit of using a 7-year-old pure-PHP implementation of Blowfish when mcrypt gets the job done much better and faster? OwnCloud's install instructions actually require a bunch of PHP extensions. They could have just thrown mcrypt into that list.
Why is for example http://code.google.com/p/relay/ not a cloud solution? Is it only a marketing term or does functionality like being able to syncing from multiple devices make something a cloud?
If "extendable" is the criteria, then any directory manager is a cloud because you can easily write a plugin and extend the functionality.
Though I understood it after visiting some pages, was really confused on visiting their front page as to what the product is about.
Skeptic about how successful they would be.
They are releasing version 4. I'd assume some success on versions 1 through 3 or the project would have been abandoned.
I'm curious on how it performs with thousands of users. I'll probably run a few tests.
And brush up my PHP.
Besides, being a PHP application, you may even be able to deploy it to shared hosting. Not bad.