Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Are you sure? According to this: https://wiki.mozilla.org/Labs/Weave/Sync/1.1/Setup it says the passphrase you use is sent in the clear (over HTTPS) to mozilla every time you get the data. That implies that while the data may be stored encrypted client-side, it's decrypted or at least verified server-side.


That is an old page, back when it was a labs project called Weave.

Try this: http://support.mozilla.com/en-US/kb/what-firefox-sync#w_what...

There is absolutely no way for Mozilla to get your data, even if subpoenaed. And, if for some reason you still don't trust it, you can easily set it up on your own server.


>>There is absolutely no way for Mozilla to get your data, even if subpoenaed

There needs to be more assurances like this in the world.


Okay, how do I set it up on my own server? If that link is old, where's the updated one?


The encryption key and the password are two separate tokens. The password is supplied by the user, while the encryption key is a randomly-generated 26-character string. (In some earlier versions of Firefox Sync, the key was also supplied by the user and was called a "secret phrase.")

The password is sent to the server, but the encryption key is not. For more info, see: https://support.mozilla.com/kb/where-can-i-find-my-firefox-s...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: