Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I came across cryptpad as cryptpad.cz but couldn't figure out who was behind it at the time. At least with this link you can get to at least one seemingly legit dev, which makes me take it more seriously. Is cryptpad.cz a fork of this or vice versa?


cryptpad.cz seems to be one of the many instances of CryptPad. I don't know who is behind.

CryptPad.org is the official website of the project (and cryptpad.fr an instance maintained by the original devs).


CryptPad is developed by XWiki as a side project.


I feel like side needs to be precised a bit. Although it admittedly doesn't generate nearly as much revenue as XWiki, several people are paid full time to work on it, and it receives public grants. It is an important project for XWiki SAS.

(I work for XWiki, on XWiki though)


Do you know of any publicized auditing done on the E2E aspect of it? Curious about that since it's part of the name and a prominent publicized feature.


I'm from the CryptPad team

There is our white paper on the security features of CryptPad: https://blog.cryptpad.org/2023/02/02/Whitepaper/

In terms of audits, we don't have the funding for formal audits but a couple years ago the European Community paid a bug bounty https://commission.europa.eu/news/european-commissions-open-...

We received some interesting reports but not as much on the cryptography than on web related issues

Ludovic


Thanks. Isn't vouching for other online instances a bit risky? Wouldn't you have to constantly verify the source is unmodified in an automated fashion for those instances you don't control?


Interesting point. We should add some warnings about this.

Ludovic, from the CryptPad team.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: