Skip to content

Comment on EncFS Security Auditparent

Comments

Boxcrypter uses EncFS. Combined with the vulnerabilities discussed in this audit, this is pretty bad.

Is the current, non-EncFS compatible version open source for the crypto components or audited by anyone reputable? If not we don't necessarily have any reason to believe it's safer.

Indeed, a priori one would have to assume it less secure than an open-source implementation that has been reviewed by experts. "We built our own" merely amounts to security through obscurity.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.