Posting here as I’ve seen Sync.com menitoned in the past in this sub. First, it’s perplexing to see so many reviews online pointing out that Sync.com is end-to-end encrypted (e2ee) and that Sync.com does not have access to your unencrypted data, when at best what should be said is “it’s closed source, and the company claims it’s e2ee and zero-knowledge”. But anyway…

I signed up to see if I can verify anything, and turns out you can verify that it’s not e2ee and zero-knowledge. I uploaded a file, then shared it and Sync.com gave me a link that I can pass to friends. The link has no hash parts (that are seen only by the local browser), it looks like this:

https://ln5.sync.com/dl/XXXXXXXXXX/XXXXXXXX-XXXXXXXXXX-XXXXXXXXX-XXXXXXXXX

Putting that link in any browser gets you the unencrypted file directly - there is no password being asked.

The same URL is logged by the Sync.com server as well whenever someone requests it, hence not only can Sync.com also retrieve the unencrypted file themselves, but if it was stored encrypted then in order to produce that link that gets the unencrypted content, Sync.com must have access to your encryption key (synonymous with knowing your encryption password) … so it can’t be stated either that if you share files then those files lose e2ee somehow. What is clear is that Sync.com is not e2ee (unless your e2ee definition allows the host to know the encryption key).

Basically, it’s at best server-side encrypted (like most of them are, or claim they are).

  • dr100@alien.topB
    link
    fedilink
    English
    arrow-up
    1
    ·
    10 months ago

    Use rclone. If the service doesn’t support it then it isn’t worth it, even for free. There is no point wasting time discussing and inferring the behaviour of some opaque system you don’t know what it does and most likely it doesn’t do what it says on the tin.

    • chrisprice@alien.topB
      link
      fedilink
      English
      arrow-up
      1
      ·
      10 months ago

      I still hope to one day make a desktop OS do full system restore that uses rclone. Break system, buy new one, feed decypt key and server info during OOBE, click go. Desktop restored. Completely.

      We can do it. We literally have the technology.