Add Internxt as a Drive alternative and as a Send tool

You just replied before me. Google Ads are present on the home page the others are in the portal.

Thanks a lot. I’ll be sure to forward this information to the relevant teams. Please feel free to let me know of any other concerns you might have; I assure you I will personally message each person responsible so actions can be taken to improve the platform.

1 Like

Also please do something about the claim of encryption of files on your home page.
For all i see the files are uploaded directly to OVH in plain.
I am actually not even able to upload files usng Firefox ¯_ (ツ)_/¯.

acually now also see the portal connects to mailerlite, yet another marketing tool

1 Like

I feel we have deviated a lot from the initial subject of the post. I am trying to provide information about users’ concerns here and gather valuable feedback.

However, there is a distinction between feedback and false claims, so I have to be very clear here, we never upload any user information to any of our servers that has not been encrypted. And our data is sharded and distributed among several servers across Europe.

Regarding your feedback referent to our newsletter tool, I would like to ask your input on how would you approach marketing for a privacy & cybersecurity-oriented platform? We need some essential tracking data, even if completely anonymized, to measure our performance.

1 Like

You can ask users to opt in. Use privacy friendly solutions such as Plausible for statistics. Don’t load marketing tools on your page directly snitching the IP of users without consent.

Its not selling that you don’t understand this in all honesty. Privacy by design doesn’t seem at the core of your values. I care more about this than you making changes to be “compliant”.

I can’t see the file being encrypted before it’s attempts to send it, but i am open to see it from your side.

3 Likes

@ph00lt0 This is one of the reasons we are fully open-source, So anyone can check the full encryption logic themselves. Here’s the logic that encrypts the files before being sent to the server: drive-web/NetworkFacade.ts at 184114210b1d2e15c02a605df9704304144be705 · internxt/drive-web · GitHub

Also, here is a snapshot of a package sent with my own account

Regarding the questions @user_of_privacy made about the issue SECURITUM-226409-019: Zero-knowledge encryption policy violation” in our audit. I just spoke with our lead dev, and he confirmed the issue has been addressed and fixed.

1 Like

The report claimed that zero-knowledge encryption is not present, which is one of the minimum requirements for any cloud product before listing them on a privacy guide.

Given its critical nature, can we request that the Internxt team either share commit IDs or provide a revised report?

1 Like

Of course, here’s the commit: [_]:(chore) Remove env variables prefix, improve API url usage by PixoDev · Pull Request #133 · internxt/drive-mobile · GitHub

Hash: 7ea7937c47163eb5d83132e1db010cdb680c0632

1 Like

Thank you for sharing the code link! May I suggest that your team seeks the advice of a cryptography expert or enthusiast to review your sign-up API? I believe there are significant concerns that need to be addressed.

As a personal opinion, I would recommend that the Privacy Guide team proceeds with caution. I don’t mean to offend Internxt team, but it appears that as of today, Filen or Mega may be in significantly better shape.

3 Likes

Thanks a lot for your feedback. I will pass this on to our devs for consideration. And no offense taken; we know being in the fire is the only way to temper a good shield. We will continue working hard and improving until we are worthy of your recommendation.

3 Likes

I must say, that after using Internxt for a few months, it is at best a beta product. Many many bugs remain, the uploading/downloading speeds are incredibly slow, and the company has a very shady past (see here, here, and more if you search for it).

I recommend huge caution to be taken before using it for now.

6 Likes

Last version of Internxt: 2.0.6 (released last week)
Last version with a binary (at least .appimage) 1.9.9: 27/04/2023 (11 months old)

Let us know when they support at least a flatpak or all version have a appimage.