this post was submitted on 20 Jan 2025
41 points (97.7% liked)

Privacy

32875 readers
1083 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

If I pair my Android phone and my laptop, I can share files over Bluetooth from the phone to the laptop. I've started finding this a really convenient method for me to send files to a Linux laptop without needing to install a separate app on either the phone or my laptop. Especially when I'm away from my home network (I use SFTP at home).

How secure is this? Is there encryption by default and could someone else nearby with a receiver potentially decode the file you're sending?

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 10 points 1 day ago (10 children)
[–] 0x0 3 points 1 day ago (1 children)
[–] [email protected] 3 points 1 day ago (1 children)

No, thanks:

It uses a WebRTC peer-to-peer connection. WebRTC needs a signaling server that is only used to establish a connection. The server is not involved in the file transfer.

If your devices are paired and behind a NAT, the PairDrop TURN Server is used to route your files and messages.

[–] [email protected] 2 points 1 day ago* (last edited 1 day ago) (2 children)

What's so bad about servers?

Both are open source.

The signaling server just sees the IPs of your devices and matches them by roomID.

The turn server sees only locally encrypted files and your IPs (and it is used only IF you are behind a NAT).

As far as I see, there is no way for anything bad happening, but I am happy to learn if you know something. If you need it for a proof, I'd gladly give you some of my IPs and encrypted files - see what you can do with them.

[–] [email protected] 2 points 16 hours ago (1 children)

My concern is has more to do with metadata, wich can be collected. If there's a local alternative or a self-hosted one for something, I'm more inclined to use these than something that depends on a third party.

[–] [email protected] 2 points 15 hours ago* (last edited 15 hours ago) (1 children)

You can selfhost PairDrop though. Including the signaling and turn server. It's open source.

[–] [email protected] 2 points 15 hours ago

Ok, that's great!

[–] [email protected] 3 points 1 day ago (1 children)

I'd rather not upload my files on remote servers. No matter if open source or no

[–] [email protected] 3 points 1 day ago (1 children)

The file does not get uploaded to remote servers. It passes through them, fully encrypted, and the server does not have the keys to decrypt your files.

[–] [email protected] 3 points 1 day ago (1 children)

passes through them

What does this mean vs uploaded?

[–] [email protected] 1 points 15 hours ago

It's transient.

load more comments (8 replies)