Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"No one but the recipient will ever be able to access your files."

Why can I directly access and download the file shown in the demo video? Why is it transferred in the clear via HTTP? http://www.sendrail.com/file/516885724/ResumeTemplate.docx

Just wondering why there isn't some type of authentication/authorization going one. i.e. If your delivery method is to a Facebook friend, why not require authenticating them to Facebook before granting access to the file?

Is the only security in place knowing a 9-digit number + filename?



Unless they have the URL to your files, in which case, anyone can download your files.. similar to public DropBox files.

I think the "will ever be able to" verbiage is a bit misleading.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: