# Is filen.io not secure enough?

**URL:** https://discuss.privacyguides.net/t/is-filen-io-not-secure-enough/14874
**Category:** Questions
**Created:** 2023-11-06T09:56:14Z
**Posts:** 42

## Post 1 by @record2957 — 2023-11-06T09:56:14Z

Hello I am trying to use [filen.io](http://filen.io) to sync photos. It is zero knowledge storage as I know. But why is it not recommended by privacyguides? Does it have weak security even it is zero knowledge? Or just because the server is located in Germany rather than Switzerland?

Is there any reasons for me to avoid [filen.io](http://filen.io)?

---

## Post 2 by @eudyp — 2023-11-06T10:18:55Z

Hey, there’s actually quite a bit of discussion after searching the forums.

Regarding this link, [https://github.com/privacyguides/privacyguides.org/pull/345](https://github.com/privacyguides/privacyguides.org/pull/345)  
it seems they are not competent enough in security. Although I’d like to find an alternative to Google Photo, this may not be a good choice.

BTW, just because it’s not mentioned doesn’t necessarily mean it’s not recommended.

---

## Post 3 by @faxe — 2023-11-06T11:52:36Z

If you’re looking for a Google Photos alternative, [ente.io](http://ente.io) might be for you.

---

## Post 4 by @record2957 — 2023-11-06T12:40:23Z

So the reason why [filen.io](http://filen.io) is not recommended by PG is because filen’s encryption doesn’t use strong encrypting algorithms enough? Is it not secure enough like MEGA?

Filen is open source now right?

---

## Post 5 by @record2957 — 2023-11-06T12:41:10Z

I considered using [ente.io](http://ente.io) but It doesn’t offers storage larger than 2TB.  
And also there is lifetime license in [filen.io](http://filen.io). So If filen’s encryption is strong enough, I think filen would be the better choice.

---

## Post 6 by @record2957 — 2023-11-06T12:45:04Z

Also with filen we could sync other files too not only photo.

---

## Post 7 by @anon73250778 — 2023-11-06T15:01:59Z

> [@record2957](#):
>
> lifetime license in [filen.io](http://filen.io).

Always remember, its not _your_ lifetime, its filen’s _business model_ lifetime. They could either go bankrupt, just not honor it, or forcibly switch you to a recurring payment _in the future_. This applies to _all_ lifetime guarantee.

---

## Post 8 by @record2957 — 2023-11-06T16:05:08Z

Thank you. I know that about lifetime account. I just want to know expert’s opinion if filen is safe enough to use so I can use it. Because it sounds great for me.

---

## Post 9 by @Equinox — 2023-11-06T16:58:51Z

I’m not really sure but every time Filen gets mentioned this article pops up. But it’s from 2021, maybe things changed over time?

---

## Post 10 by @record2957 — 2023-11-06T17:24:37Z

I agree. in that article Filen is mentioned not open source. But it is open source.

---

## Post 11 by @vicky — 2023-11-07T04:42:29Z

Is it just me or filen’s new notes look like copy and paste from standard notes

> **[Filen Hub](https://filen.io/hub/)**
>
> Discover the latest updates, news, tutorials, and feature releases from Filen — your secure, zero-knowledge cloud storage solution.

---

## Post 12 by @eudyp — 2023-11-07T06:28:32Z

A product founded after 2020 that claims to be secure but once used RSA encryption is a red flag to me.

[filen-desktop/src/components/app.js at da3a59c808a0103c2d3750e3acda458e1208b99c · FilenCloudDienste/filen-desktop · GitHub](https://github.com/FilenCloudDienste/filen-desktop/blob/da3a59c808a0103c2d3750e3acda458e1208b99c/src/components/app.js#L2580-L2582)

The linked GitHub discussion thread provides additional concerns and sources. This makes it unlikely that I would choose this product first.

Regardless of whether I end up using it based on my own security policies, it is still important to be aware of the software’s past problems because they reflect the developers’ understanding of security.

---

## Post 13 by @Reset0609 — 2023-11-07T07:58:20Z

> [@vicky](#):
>
> Is it just me or filen’s new notes look like copy and paste from standard notes

my thoughts exactly, as a standard notes user, after trying it out yesterday. I dont have much doubt that they lifted it from standard notes. Its basically the paid version of standard notes for free. And also, the chat function seems to resemble the one in mega though Ive never used it so I might be wrong on that one

---

## Post 14 by @record2957 — 2023-11-07T12:06:20Z

> [@eudyp](#):
>
> Regardless of whether I end up using it based on my own security policies, it is still important to be aware of the software’s past problems because they reflect the developers’ understanding of security.

Than what is your recommendation?

---

## Post 15 by @eudyp — 2023-11-07T12:51:01Z

To be honest, everyone has to build their own threat model.

For me, the most important photos are backed up with Kopia using the 3-2-1 method. I regularly transfer important photos to the backup.

For photos that I need to access at any time, I haven’t seen a solution that meets my needs. Since the amount is not large, I currently store them on my phone, which does not take up too much space.

I don’t think the current method is really good, but it’s what we’re doing for now.

Proton is currently working on a photo application that could be a good option.

---

## Post 16 by @Regime6045 — 2023-11-07T15:11:27Z

That’s not a problem as long as they don’t violate any license. It seems that both Standard Notes and [Filen.io](http://Filen.io) are AGPL3.0-licensed, so it’s fine.

---

## Post 17 by @Reset0609 — 2023-11-09T15:39:22Z

sure, it should be just fine from a legal perspective. But I have to wonder if the recent Standard Notes drama, where it was going to turn proprietary, is not related, given the timing that the fact that their concern was that someone could just rebrand and redistribute their product.

---

## Post 18 by @6c85jz248brg68s51glfwz1447os — 2024-01-02T14:58:20Z

> [@eudyp](#):
>
> A product founded after 2020 that claims to be secure but once used RSA encryption is a red flag to me.

 ![2024-01-02 00_06_30-Is filen.io not secure enough_ - Privacy _ Questions - Privacy Guides - Brave](//forum-uploads.privacyguidesusercontent.com/original/2X/5/525d0cc6f73dfebf4255a5c116505052aeff94ab.jpeg)

---

## Post 19 by @dngray — 2024-01-02T18:47:01Z

That is only used for the signed cert, which is rotated anyway every 3 months. It does not use “RSA” encryption.

Further everything on this site is actually public, which is not the case for files stored in Filen, so your argument is irrelevant.

---

## Post 20 by @ph00lt0 — 2024-01-02T22:49:10Z

Ente does offer more storage if you need. You can contact them to get more storage. @vishnukvmd correct me if I am wrong.

---

## Post 21 by @6c85jz248brg68s51glfwz1447os — 2024-01-02T23:06:19Z

Very good. So would you care to tell us what in capacity Filen uses RSA? I cannot help but notice @eudyp omitted to inform this thread.

---

## Post 22 by @ph00lt0 — 2024-01-02T23:16:57Z

> [@6c85jz248brg68s51glfwz1447os](#):
>
> Very good. So would you care to tell us what in capacity Filen uses RSA? I cannot help but notice @eudyp omitted to inform this thread.

This link is literally in the thread above linking to the source code using RSA for encryption.

> [@eudyp](#):
>
> filen-desktop/src/components/app.js at da3a59c808a0103c2d3750e3acda458e1208b99c · FilenCloudDienste/filen-desktop · GitHub

---

## Post 23 by @6c85jz248brg68s51glfwz1447os — 2024-01-02T23:17:42Z

So tell us what it means.

---

## Post 24 by @ph00lt0 — 2024-01-02T23:18:43Z

What is here to tell other than that it is using RSA for encryption? Not sure what else you need to know.

RSA is not deemed secure enough in the industry. If we need to explain this you should get back to studying cryptography before we can continue this conversation.

---

## Post 25 by @6c85jz248brg68s51glfwz1447os — 2024-01-02T23:23:28Z

RSA is used on this very site… so clearly it isn’t completely obsolete. How does Filen use it?

> [@ph00lt0](#):
>
> RSA is not deemed secure enough in the industry. OlIf we need to explain this you should get back to studying cryptography before we can continue this conversation.

Uh huh… which is why RSA is post quantum ready, correct? After all, I don’t have to provide a credible source if you don’t.

Did you just tell me to _eduskate myself, sh!tlrod!_ ?

---

## Post 26 by @ph00lt0 — 2024-01-02T23:31:02Z

You may not see it yourself but bu writing this it shows you have no idea what you are talking about.

But for the sake of it:

- [Seriously, stop using RSA -The Trail of Bits Blog](https://blog.trailofbits.com/2019/07/08/fuck-rsa/)
- [https://www.thesslstore.com/blog/is-it-still-safe-to-use-rsa-encryption/](https://www.thesslstore.com/blog/is-it-still-safe-to-use-rsa-encryption/)
- [RSA Is Dead — We Just Haven’t&nbsp;Accepted It&nbsp;Yet](https://www.forbes.com/sites/forbestechcouncil/2021/05/06/rsa-is-dead---we-just-haventaccepted-ityet/)

You could literally just google this shit. Also get again as @dngray using RSA for a TLS certificate is a completely different application of cryptography. Your replies lack any understanding of this. Applications have different requirements and importance.

Your comment about quantum. No RSA is probably not quantum safe. This is a big issue in the industry. Yet again not really trivial for a website like privacy guides. ECDSA will likely be a better alternative although that remains to be seen. If you want to learn more about actual quantum safe you should read on [https://openquantumsafe.org/](https://openquantumsafe.org/).

---

## Post 27 by @6c85jz248brg68s51glfwz1447os — 2024-01-02T23:32:47Z

And yet you’ve still omitted to tell us how Filen uses it.

---

## Post 28 by @ph00lt0 — 2024-01-02T23:35:10Z

Omg dude. You’re going in mute. If you can’t read the source code that’s your problem. I am not going to explain it. The fact fhat filen uses it for encryption is the issue. You really do not seem to want to hear it. It isn’t important what even is encrypted using it. Appears to be a lot but it is inrrevant. Using RSA for any encryption in this way is just showing incompetence.

---

## Post 29 by @6c85jz248brg68s51glfwz1447os — 2024-01-02T23:46:23Z

FIrstly, what nice, expansive edit more than three minutes after the fact. Perhaps it’s just me but it really says something. As to what I’ll leave it to this thread’s polite audience’s imagination.

Secondly, you again neglect to respond to the query. Let me refresh your memory: how does Filen use RSA?

Thirdly, If you think curves “will likely be a better alternative” then I can only thank you for spotlighting the threshold for what it takes to be a “PRIVACY WIZARD” in

> **this so-called “community”.**
>
> Dilettantes.
> 
> (Edit: … and then the PRIVACY WIZARD blocks me. How telling. Maybe he’ll have better luck LARPing on Twitter.)

---

## Post 30 by @dngray — 2024-01-03T07:47:37Z

@6c85jz248brg68s51glfwz1447os

RSA is sufficient. While extremely small RSA keys should not be used, (anything under 2048bit). RSA 4096bit is still secure enough. The main reason for moving away to EC related curves is because of smaller keysize/speed, not because of quantum resistance (which neither are).

---

## Post 31 by @6c85jz248brg68s51glfwz1447os — 2024-01-03T07:59:14Z

Exactly. Generally speaking, curves & anything less than RSA-4096 aren’t going to protect against so called ‘harvest now, decrypt later’ … but I presume we’ve all heard of one E. Snowden.

RSA-2048 is still perfectly acceptable if one’s goal is commonplace DPI evasion as a part of a layered strategy. Even the LARPing ‘wizard’ ITT hinted to the metaphorical idiom of ‘the right tool for the job’… in far more crude terms but no matter. That still doesn’t answer the question posed:

In what capacity does FIlen use RSA?

---

## Post 32 by @dngray — 2024-01-03T08:51:26Z

RSA isn’t used for encryption. They use 256-bit AES for that.

The RSA encryption looks like it’s used for some kind of API request that shows the files the user is downloading. It also looks like it has something to do with shared folders.

I also didn’t see anything about 2048 bit encryption there with it.

---

## Post 33 by @6c85jz248brg68s51glfwz1447os — 2024-01-03T09:14:17Z

Interesting, isn’t it? At no point has @eudyp stuck his head back ITT to defend his position… & I know you’re seeing the notifications, ‘Penguin’. Meanwhile you & I, Gray, had a pleasant little exchange about the various uses of while everyone™ else falls into a tizzy at the mere mention of RSA.

This really is a fun little site; highly entertaining if I may say so.

You have good intuition: it’s related to the public key exchange before pushing the share’s metadata when sharing strictly between Filen users.

#TiawanNumber1

---

## Post 34 by @ph00lt0 — 2024-01-03T09:22:29Z

ECDSA is arguably better, but I agree that it is likely that neither will proof secure enough against quantum. However, that for what it is worth is all theory.

> RSA isn’t used for encryption. They use 256-bit AES for that.

There is indeed no **file** -encryption using RSA here, from what I see. However, there is also no good excuse to encrypt metadata using it. It just isn’t a good idea. It makes no sense to use RSA here while better options are available.

Secure enough? maybe. Is it a well architectured solution? probably not.

---

## Post 36 by @dngray — 2024-01-03T09:28:24Z

Keep the thread civil, or I will have to moderate Thanks.

---

## Post 40 by @rickyrooroo229 — 2024-06-05T16:21:45Z

To keep it simple, RSA is also being used by the government as well as the big wig companies. When you store data into something with RSA implemented, you run a risk (a very small risk considering their security) of having the government and these big wig companies looking at your data if RSA complies. While the chances are next to zero considering privacy law, the fact that the chance could be there is considerable enough for most people that store data for privacy

---

## Post 41 by @user_of_privacy — 2025-02-10T04:33:37Z

Let’s wait for Filen’s proper security audit first, and then we can come back on whether or not we should recommend them here. They plan to do an audit now that they did a full redesign: [Filen Hub](https://blog.filen.io/recap-2024/)

---

## Post 42 by @anon39279085 — 2025-02-10T10:26:52Z

Tbh their whitepaper is enough to tell me about their security. And it’s better than Mega at this point.
