Settings

Theme

Ask HN: Tool to share/exchange personal and confidential files

4 points by akashcoach 2 years ago · 10 comments · 1 min read


What tool do you use to share/exchange personal and confidential files with outside organizations ? Size of the files can be large in many GBs. Security is the main concern. Tool should be web based.

plz-remove-card 2 years ago

> Size of the files can be large in many GBs.

> Security is the main concern.

> Tool should be web based.

From your question it kinda sounds you actually have 3 main concerns, not just security. I can't give you any suggestions for web based tools but I can suggest:

1. Obtain a public SSH key out-of-band with the party that needs the large file and give them access to an SFTP share with that key.

2. Upload the file to a private S3 bucket and send them a signed link[1]

[1] https://docs.aws.amazon.com/AmazonS3/latest/userguide/ShareO...

  • akashcoachOP 2 years ago

    Thanks for your suggestion. Unfortunately the users of the system are not too technical so some of these steps might be too much for them. Is there a user friendly tool in this space of secure file exchange?

bobbiechen 2 years ago

Based on your non-technical users, you may want something with a Dropbox-like UI that can be self-hosted, like PsiTransfer https://github.com/psi-4ward/psitransfer .

If you're hosting in the cloud, you can improve the security posture using confidential computing like AWS Nitro Enclaves. Contact me at bobbie.chen@anjuna.io if you'd like more info on getting started with that.

runjake 2 years ago

SFTP.

For non-technical partners, we have a simple instructional document on how to download and use Filezilla[1] to connect. We haven't had many challenges.

1. https://filezilla-project.org/

  • akashcoachOP 2 years ago

    External orgs sysadmin does not allow filezila installation. That is why we are looking for a web based solution that they can access via the browser.

    • dagw 2 years ago

      Another problem I've run into more than once is that many orgs don't allow ssh out through the firewall. One project I worked on recently the client had to send and receive data via his home computer after work and transport it to/from his work computer on a USB drive. Apparently that was fine.

      • akashcoachOP 2 years ago

        That would be a strict no-no for us considering the sensitivity of data.

        • dagw 2 years ago

          Oh I am definitely not recommending this. It's just a warning of how people will work around any security protocols you put in place if they make it too cumbersome to actually get their job done. And in this case it was their secret data, not ours, so we didn't argue too much.

    • runjake 2 years ago

      If those were the requirements, I'd pay for Dropbox and use their web sharing platform.

      It's probably the least janky solution I've come across in a land of janky and insecure.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection