HNHacker News
TopNewBestAskShowJobs

rbolte

132 karma · joined December 17, 2014

submissionscomments
rbolte··on Show HN: YouTransfer – Self-hosted file sharing
Released version 1.0.3 which fixes the XSS and path traversal security issues (as well as 3 other issues, see https://github.com/remie/YouTransfer/issues?q=milestone%3A1.... for more info)
rbolte··on Show HN: YouTransfer – Self-hosted file sharing
Good catch! The XSS error was introduced with the implementation of error handling, but is a really unwanted side effect :)

I've created two issues on GitHub (https://github.com/remie/YouTransfer/issues/107, https://github.com/remie/YouTransfer/issues/108) which will be fixed in a new hotfix release asap.

rbolte··on Show HN: YouTransfer – Self-hosted file sharing
I'm not familiar with camlistore, but a first glance at the project website tells me that it has way more features and serves a different goal.

YouTransfer is basically a very simple hit & run file sharing application. The goal is to make uploading & sharing files a matter of 2-3 clicks. The files will be stored with a configurable retention time and will be deleted from the server after they expire.

YouTransfer it's not meant to help you organise your digital life, or have access to all your files remotely. It will only help you share files in a more convenient way compared to SFTP or email.

rbolte··on Show HN: YouTransfer – Self-hosted file sharing
BTW: if this concerns the youtranfer.io website (instead of the YouTransfer application), I'm actually a bit hesitant to change this. I'm currently using the GitHub site generator for convenience. There is a limited set of templates available, most of which are either ugly or have readability issues. As the website basically only consists of the README file, you can also look at the GitHub project for more information (https://github.com/remie/YouTransfer)
rbolte··on Show HN: YouTransfer – Self-hosted file sharing
Good suggestion! I've added an issue on GitHub (https://github.com/remie/YouTransfer/issues/106).

BTW: normally the files will expire within a specific timeframe and will be removed by a scheduled cleanup process. This should limit the impact, but if the system is heavily used it might become a problem.

rbolte··on Show HN: YouTransfer – Self-hosted file sharing
I'm a bit hesitant to change this as I'm using the GitHub site generator for convenience. There is a limited set of templates available, most of which are either ugly or have readability issues. As the website basically only consists of the README file, you can also look at the GitHub project for more information (https://github.com/remie/YouTransfer)
rbolte··on Show HN: YouTransfer – Self-hosted file sharing
The problem with ACL is that I'm worried it will make the project more complex. I've added an issue on GitHub for future reference (https://github.com/remie/YouTransfer/issues/105)
rbolte··on Show HN: YouTransfer – Self-hosted file sharing
Are you referring to the generated GitHub pages on http://youtransfer.io or to the demo instance (http://demo.youtransfer.io) which is the actual application?
rbolte··on Show HN: YouTransfer – Self-hosted file sharing
Basically... yeah, if you do not take any additional security measures, anybody can just "dump" files on your server.

You could opt for the S3 storage provider, which will dump the files to Amazon AWS instead.

The YouTransfer project does not implement access control or SSL, so it is highly recommended that you look at the hosting options on the Wiki (https://github.com/remie/YouTransfer/wiki/hosting).

I'm afraid there is not much the project can do concerning upload speeds of individual connections at home :)

rbolte··on Show HN: YouTransfer – Self-hosted file sharing
Currently, the files are stored as a flat file list on the file system using their randomly generated token to create a [token].json and [token].binary file. The JSON file contains meta information, the .binary file is the actual file.

Using the default settings, you would get something like "./uploads/0b692a00635682fabc78b6a50655242c.binary" in the application directory.

I've already has plans on making it possible to change the interface, for instance not allowing direct download from the homepage. I could ament this with the feature to send email notifications to the system administrator upon successful file transfer. The combination of both would allow you to use YouTransfer.io as a public drop box for files. Does this sound about right to you?

rbolte··on Show HN: YouTransfer – Self-hosted file sharing
:D

How about Proxima Nova? (http://www.marksimonson.com/fonts/view/proxima-nova)

rbolte··on Show HN: YouTransfer – Self-hosted file sharing
Thanks! I'm glad I could help :)
rbolte··on Show HN: YouTransfer – Self-hosted file sharing
Any suggestions?
rbolte··on Show HN: YouTransfer – Self-hosted file sharing
And it's done. The 1.0.2 hotfix is now available with the token generation fix as well as 2 other enhancements.
rbolte··on Show HN: YouTransfer – Self-hosted file sharing
It's not really related. YouTransfer.io uses DropzoneJS as the file transfer UI for javascript enabled browsers.
rbolte··on Show HN: YouTransfer – Self-hosted file sharing
I've opted for the 16 bits version right now as it fits better in the UI. There will be an additional issue to deal with improving the bitrate as well as making a suitable UI for it.

EDIT: I'm using `crypto.randomBytes(16).toString('hex')` to be precise

rbolte··on Show HN: YouTransfer – Self-hosted file sharing
It has less features :)

The success of services like WeTransfer or Dropbox is that it is dead simple to use. It does one thing (sharing files) and makes this as easy as possible.

Seafile seems to be easy enough, yet still has a multitude of features compared to YouTransfer. OwnCloud simply has a whole different goal. It's not about sharing files, it is about organising your entire cloud presence (with e-mail, calendar, foto's, etc).

With YouTransfer, you can have the same ease-of-use but on your own terms. It runs on your own servers, with your own (secure) storage. You are in full control.

Given that it is also published as an NPM package, YouTransfer can be modified to suit your specific needs. This makes it interesting for companies to rebrand it and use it as their file-sharing system.

rbolte··on Show HN: YouTransfer – Self-hosted file sharing
Working on it as we speak! I'm currently running the tests and hope to have a 1.0.2 hotfix ready by lunch.

EDIT: The 1.0.2 hotfix is now available with the token generation fix as well as 2 other enhancements.

rbolte··on Show HN: YouTransfer – Self-hosted file sharing
Thanks!
rbolte··on Show HN: YouTransfer – Self-hosted file sharing
Actually... you don't need any of those. It's only a suggestion. You can also install NodeJS, download YouTransfer, set the port to 80 and run it.

However, it is highly recommended to either use Docker, a reverse proxy, any of the PaaS providers or a combination of the above.

EDIT: I've updated the wiki with additional information on running it locally.

rbolte··on Show HN: YouTransfer – Self-hosted file sharing
You're right! I was actually still working on the demo and am a bit overwhelmed by the attention generated by the HN show case. I've update the README and website, thanks!
rbolte··on Show HN: YouTransfer – Self-hosted file sharing
Thanks for scrutinising the codebase! You are absolutely right that there is no need for creating a hash. This was just plain laziness on my part. I've created an issue (https://github.com/remie/YouTransfer/issues/101) to change the token generation.
rbolte··on Show HN: YouTransfer – Self-hosted file sharing
YouTransfer is a simple but elegant self-hosted file transfer & sharing solution. It is an alternative to paid services like Dropbox and WeTransfer by offering similar features but without limitations, price plans and a lengthy privacy policy. You remain in control of your files.

Created to be installed behind the firewall on private servers, YouTransfer aims to empower organisations and individuals that wish to combine ease-to-use file transfer tooling with security and control.

You can watch a live demo at http://demo.youtransfer.io

If you want to see it in action on your own environment, you can use the Docker image (https://hub.docker.com/r/remie/youtransfer/) or NPM package (https://www.npmjs.com/package/youtransfer)

rbolte··on Show HN: YouTransfer – Self-hosted file sharing
You can see a demo at http://demo.youtransfer.io
rbolte··on Creating a custom Git flow visualization
Thanks for the feedback on the GitHub permissions. We will evaluate the necessity of the current scopes and revise them or better explain their use in the Privacy Policy. As the domain name already suggest: this is a BETA version. We are still working out the details of our service!