This is a great insight, explained well. Thank you for it.
232 karma · joined March 2, 2022
Could you elaborate on this? Which defaults do you consider insecure? Are there ways to trivially change some values for more security?
Not pushing back on your statement, just curious to know more about it.
It seems that although Seafile's implementation leaves something wanting (I think Option #1 of never sending the key to the server may be a superior option), the sheer fact of the feature's availability trumps the sub-optimality of its implementation. The author also implies that the implementation is "good enough" for his (and presumably most others') use cases.
Here is the reference I used for creating my own task management meta-model: