"It's ridiculously difficult to share a single file online without a bunch of hassle.
Most sites either riddle their pages with ads so you have to guess where the correct download button is and usually restrict useful features to their premium users.
All those useful features have been added to NoFile and made available for anyone who wants to use it - all free from ads, registrations, payments and it respects your privacy.
Here are some of the current features (more to come):
* Simple upload process compatible with nearly all devices - accepts files as large as 10 GB to be uploaded
* Upload & download files without Javascript enabled (nearly all features are still available, although the site runs smoother with Javascript enabled)
* Password protect files (hashed with SHA256)
* Ability to encrypt files with AES-128 on the client-side before uploading to the server for secure storage (BETA)
* Easily view the metadata of a file (file type, dimensions, upload date, size, etc.) on its download page (URL to a live demo below)
* Preview files (PDF viewer, video/image/audio previews) before downloading (see demo URL below)
* All transfers are made securely over HTTPS to prevent malicious users from viewing what you're downloading/uploading (forced SSL)
* Securely view your upload history without having to create an account (history is stored in your browser's local storage)
* Save files directly to Dropbox (Dropbox scripts are only loaded when button is pressed to protect your privacy)
* No tracking codes and no third-party CDNs are used for external scripts, CSS or fonts in order to protect your privacy
To start uploading your own file(s) within seconds (without signing up): https://nofile.io
If you have suggestions, a complaint or any features that you would like to see added then feel free to leave a comment or use this contact form: https://nofile.io/contact/"
> It's ridiculously difficult to share a single file online without a bunch of hassle. Most sites either riddle their pages with ads so you have to guess where the correct download button is and usually restrict useful features to their premium users.
Imho, if you really want to be the "Google of file-sharing", then the UI should be a lot less distracting.
I have to say I humbly agree with this advice - the NoFile.io name got me clicking (the most difficult hurdle) - then when stuff started to animate I thought 'oh' and closed the window. Perhaps this is small minded of me :-)
"Google of file-sharing" would be a too heavy title to hold right now.
The animations are there in the background to give the site a comfortable touch, but it should be easy to distinguish them from the actual site content (e.g the download button comes inside a "box" with a different background color and animated icons hidden underneath).
Perhaps it would be useful to add an option that toggles the animations on/off.
Seems interesting, consider adding the option of "link to file directly", that is without a "file landing page". Enable it for paying customers if you have to.
Also, I tried downloading my own screenshot but nothing actually happens. (The loader does pop up)
Downloading & preview does work for an unencrypted file.
"How can I view my history? I think I've clicked every link available but I can't find this at all."
The button had been hidden for some users due to a bug.
It's been fixed and you will be able to see it after refreshing the page, thanks for pointing it out.
"Same for this. There is no such option to be found."
This feature was disabled shortly after the launch due to a bug. It'll be added again as soon as possible.
What's different to so-called 1-click hosters (rapidshare, mega, uploaded, ...)? What's your business model? How do you want to keep DMCA claims at bay? Does this work mobile?
What's different to so-called 1-click hosters (rapidshare, mega, uploaded, ...)?
The main difference is that nearly all of these hosts specialize in a specific type of storage.
As an example MEGA forces all users to client-side encrypt files before uploading which is useful for sensitive files, but it comes with the cost of incompatibilities with older browsers and devices which can't decrypt/download the files.
Uploaded provides lots of space for the uploaders, but then pushes all users to its premium plan.
The site is ridiculously slow to use as a free user as they cap download speeds to 50 KB/s (they bump it up to a 70 KB/s if you take the time to sign-up).
NoFile bundles all the perks of the different hosts and gives the user more options and fewer limits.
You can upload large files and choose whether you want to password protect, encrypt or disable previews for your file while still giving the downloaders speeds of at least 2 MB/s.
It's just a simple file host that allows you to share files without having to worry about the downloaders being infected with a virus, not being able to download
What's your business model?
At the moment there is no revenue source.
As costs for the hosting go up, there will be a more "humane" premium plan added in the future, but it will targeted to very frequent users and as a free users you won't be affected by the changes.
How do you want to keep DMCA claims at bay?
If a valid DMCA request is sent in together with a link then we will be forced to respect the content creator and take the link down.
Does this work mobile?
This works on every single device regardless of whether you have Javascript enabled or not.
If you however enable the client-side encryption feature (currently in BETA) which is disabled by default then users on older browsers and devices won't be able to download your file.
So what makes you think your fate will be any different than that of all the other free file hosts that have had to resort to advertising in order to survive?
The site will simply not operate with large margins like other sites. The cost of keeping the servers and development running will be covered by a premium plan that's targeted to heavy users.
Isn't storing and serving terabytes of stuff pretty expensive? How many heavy users do you think you'll manage to win over in the first place, much less convince them to pay for the privilege of uploading their 100GB of illicit car diagnostic software to your website? Do you have an actual niche you plan to target?
I don't mean to be negative, it's just that I've seen the transition from free to freemium to ad-supported to Rapidshare to dead happen over and over again. These services don't seem to operate with large margins - from the outside, it looks more like all of them are on the brink of bankruptcy.
I generally see prices of 2 cents per gigabyte per month for active storage, even less, most under half a cent per gigabyte per month for long-term archival. Assuming there were willing to fork out 10 dollars a month, they would be able to get around a terabyte of storage.
Lets imagine our average citizen uploads quarter of a gigabyte, that means 4,000 visitors uploading files per $10 client. Assuming you can keep other costs really low, it's not too outrageously expensive.
A few years ago bandwidth and storage was much more expensive than it is today.
Rapidshare was a service that had to swiftly and reluctantly change their business model. They were operating out of large offices with over 60 employees and due to the change they saw a sudden drstic drop in revenue.
Rapidshare's financial information isn't public since it's a private company, but one could argue whether they were actually losing money or not making the profits that they expected at the time of the shutdown.
I think Rapidshare earned tons of money. At one time RS was the go-to filehost for pirated material. They had almost anything you wanted, and they seldom removed files.
Then came the FBI raid against various filehosts. I remember few of the other hosts got taken down and charged, while others shut their site down as precaution. I remember Rapidshare starting their decline during this phase, something tells me Rapidshare did it on purpose and 'ran away' with the earned money before the feds got them.
This is a misnomer, as bandwidth gets cheaper, file sizes get larger due to technological advance. Think about the average size of a photo from 2006 and from 2016.
Sounds exactly like other services that offer premium file services, how is this different? Also, while I know you're claiming this doesn't take away from the free users, it clearly does.
Your post reads like someone who knows nothing about the difficulties or complexities of this space, the economics, what customers will or will not pay for, or the legalities associated. I've heard this same pitch (or a similar variant) many times in the past, and the result is always the same.
The most concerning aspect of your model is charging users for download speed. That might cause users to pay you, but it puts an incentive on business to host questionable content. Megaupload and Rapidshare were doing the same thing.
Protect sensitive files with encryption.
Only users with the URL will be able to view it. "
This is not encryption - you should change the copy to tell what encryption is used (AES-128 from the info here), even if it's beta. Some more information on that will be welcome.
They may be encrypting the file with a parameter passed in the URL. In this case, assuming no logs are kept, it would be a reasonable encryption setup.
The encryption key is passed after the hash (#) in the URL.
Therefore the keys are never sent to the server over the HTTP request (more info about this can be found here: https://nofile.io/security/).
"Your file is first securely encrypted using a secret key (AES-128) with Javascript on your device.
Once it has been encrypted, the encrypted data is uploaded to a NoFile storage server over a secure HTTPS connection preventing any malicious users from seeing what you're uploading (as an extra layer of security).
Only those with the secret key (which is in the URL) will be able to see the correct content and filename - if a single character of the key varies, then the file will be unrecognizable."
You need to set this as your preferred method on the upload page.
> compete with older (& less crappy) services like mediafire?
Did you mean to infer that MediaFire was less crappy than this showcased one? Or crappier than this one? Your follow up sentence would indicate the latter.
I meant less crappy among the usual "file hosting sites". Mediafire for one is a pretty good service with 10GB for free but some times has too many annoying ads
These services (Mediafire, Zippyshare, Uppit) are among the best file hosting sites online, but unfortunately they have their issues too.
The problem being that you have to jump between different hosts depending on how large your files are and which features that you want to use (e.g Mediafire for larger files, Zippyshare from public PCs so you don't have to login, MEGA for sensitive files that you want to send securely, Dropbox when you don't want grandma's PC to get infected when you're sending her the videos from Christmas).
The goal is to create one single host that saves you from having to jump from each host and having to maintain dozens of accounts to bypass limits.
Seems pretty cool. I was actually thinking of building a similar 'accountless' file upload and sharing service, but this one is a lot better than what I was envisaging.
Question - would you, in the future allow uploading to configurable destinations, e.g. my own S3 buckets? Also, do you track the number of time a file asset was downloaded from your service so that the original uploader can check activity stats?
EDIT: Feedback - when I scrolled to the bottom of the home page, the "There is something I have to tell you" section is duplicated under itself.
Right now there's only an option to upload files to Dropbox, but the plan is to add as many useful alternatives as possible and S3 would be a good option.
The number of times a file was downloaded is currently being counted, but it isn't public. It would be an interesting idea to display it on every download page by default (similar to Imgur) and give the uploader the option of disabling it.
The duplicated info block has also been replaced, thanks for pointing it out.
What a stupid answer to that question! (it gives more info - "You can set an expiry time by pressing the "Options"-button that's next to your uploaded file, otherwise your files will float in the clouds for as long as possible." - but it still doesn't really give any answer)
Well, in all honestly they can't really say "forever" or "indefinitely" because that is really an impossibility. How long is "forever" in your estimation? 10 years? 100 years? a thousand?
In all likelihood, the internet itself might evolve into something different in that time. This service might get bought out, or shut down, or the original founders may (fate forbid) get hit by a bus next week.
Setting any sort of indefinite limit is opening themselves up for legal action if it is even one minute less than someone expects. "As long as possible" at least is honest enough to say that as long as there is enough interest to keep the lights on, they will be there.
Since there's no business model, NoFile could disappear overnight.
Without some sort of guarantee of availability, I wouldn't be able to recommend it to friends, coworkers, or family. I don't want to advertise something that is truly a great service but ends up shutting down few months from now after people start abusing it.
There is of course nothing other than our word that will guarantee the site being up.
But if the site does decide to shut down then we will be sure to notify users about this at least a month in advance in order to have time to make backups.
Just in the way of feedback (and I might be really out of the loop/not your target market!) but here was my brain-in-action after I clicked on the link from HN:
"Hmm, this looks pretty... what is it for?
It has a huge area that says "click here or drag and drop to start uploading"... but uploading what? And why?
Let's scroll down and read the 'about'!: "Fast", "Compatible", "Encryption"... um... ok but WHY?! Is it personal file storage for me (Like Dropbox?) or is it like a public FTP server? Or something else? If I drag and drop my tax return there is it suddenly shared with the entire world? Why do I want this thing?! Back to the HN comments to find out more!"
Something like that anyway! According to the comments it seems to be more like a rapidshare/mega thing - and now that I get it I'll keep this site in mind for sure!
The upload box is the first and almost only thing that you see when you go to the page and the purpose is to make the process simple so that you don't have to click through to a second page in order to start uploading.
You do however have a point as it could be confusing for some new user who haven't uploaded files before. We'll try to add an info box or some additional text to make the message more clear, thanks for pointing it out.
I guess it might be a cultural thing, but it seemed pretty obvious to me that it's something in the style of Mediafire/RapidShare/Hostr, before they all went to crap.
Localhostr was great for a while for just uploading stuff without needing to bother with accounts or RapidShare's wait-a-minute-or-pay thing. It makes sense why you scaled back the free version (I can imagine that these services quickly get expensive to run..) and started requiring accounts. But personally that's the point where it was roughly equally annoying to upload to Hostr and my own server, and so the latter just made more sense for me personally.
I like it. But I would like a more concrete answer to how long the files are kept. "As long as possible" is not really a great answer. I don't expect it to be there indefinitely, but something like "For at least 5 days. And no guarantee longer than that" would be fine with me.
It's a difficult question to answer exactly how long a file would be kept as the deletion is based on two factors:
- How active the file is (e.g if the file isn't downloaded in X days).
- How much space that's available on the storage servers.
As mentioned in a previous comment, the site's operating on small margins so the majority of the income will go to expanding the storage in order to make sure that your file is never deleted (unless you request).
At the current rate your file would never be deleted (again, unless you request it) and at a bare minimum your file will be stored for at least a week without downloads so you don't have to worry about your file being deleted before your downloaders get to it.
This will be updated in the FAQ section to avoid confusion as well, thanks for pointing it out.
I understand there is a technical aspect of how long you keep the files. But the end users probably don't really care. When I use a service like this to transfer a file to someone else, I would like to be able to write a message to the other person saying, "please download this file in X days".
I'd like to challenge you on the site name, though. Why'd you pick it? If I'm a normal user who stumbled across the site, I might be confused if a site called "NoFile" wanted me to upload files.
I might be wrong, but it seems to me that the encryption key for the file is the truncated SHA256 hash of the file itself.
This is not how you want to generate an encryption key.
Edit: also, password protection is enforced server side, and has nothing to do with encryption
The key is the truncated hash of the file for the purpose of file deduplication. However, it will not impose any security risks as the person who wishes to decrypt it would have to know the hash of the file which requires them to already know the contents of the file making it useless.
The password encryption is indeed server-side, but it is mainly there to protect the file against anyone who somehow finds/guesses the URL and it's a useful feature if you want to slightly increase the level of security without encrypting the file with AES.
> would have to know the hash of the file which requires them to already know the contents of the file
That is incorrect. Knowing the hash does not mean you know the contents of the file. You should generate encryption keys randomly, preferably using a secure random method such as that shipped with SJCL, rather than JavaScript's random API.
Unfortunately it's required for the file deduplication.
Although it slightly degrades the security it's not serious enough to impose any security risks as the attacker would already have to know the hash of the file which almost always requires them to know the contents of the files.
Random strings and numbers are also securely generated through a CSRPNG with window.crypto.getRandomValues().
Feedback: the navigation bar at the top is quite unusable from an UE point of view. The positions of the icons (and therefore the hovering position) change as the mouse hovers them. It is quite annoying.
Also, in the FAQ: "How can this be a free service? Magic"
This sounds to me as: "stfu, don't ask, you are not clever enough to understand" or "there is some dirty way to get money from you, better don't ask".
I agree with both comments, especially the faq language. Often times, lightheartedness in the tech space comes across condescendingly. A simple explanation here would suffice...and if it is truly magic, I'm all in.
Nice work, looks like an interesting project. I do think your site copy could do with some work though. It's not entirely clear from the current text what the service actually is - is it for sharing files with others, is it a Dropbox competitor or is it an S3 competitor?
The following phrase made me feel a little uncomfortable about using the product.
"How can this be a free service? Magic. In the future a paid service will be introduced offering more awesome features, but don't worry it shouldn't affect the free service."
I'd rephrase this - definitely remove the shouldn't as that tells me that while my files shouldn't be deleted, they might be.
Finally, just a minor thing, but the down arrow under the "Click Here Or Drag & Drop To Start Uploading" doesn't work for me (latest Chrome on Mac). I assume it should scroll down the page but it didn't for me at least.
Dropbox and S3 are too far from us right now and I wouldn't call them competitors.
NoFile is a simple tool that allows you to quickly share files with lots of options, nearly no limitations and at the same time as you don't have to sign in.
"I'd rephrase this - definitely remove the shouldn't as that tells me that while my files shouldn't be deleted, they might be."
You're right about that as the premium plan will never lead to files uploaded by free users to be deleted. The premium plan will only be targeted to more heavy users and won't affect the free users.
"Finally, just a minor thing, but the down arrow under the "Click Here Or Drag & Drop To Start Uploading" doesn't work for me (latest Chrome on Mac). I assume it should scroll down the page but it didn't for me at least."
The button was indeed not working and it's now been fixed, thanks for pointing it out.
"NoFile is a simple tool that allows you to quickly share files with lots of options, nearly no limitations and at the same time as you don't have to sign in"
I have a tough time trusting a new service where I cannot figure out where this business is located / registered, where they have a physical presence, the person/team who built this service. Having more details in an About Us section would help it look more legit.
Yes, completely positive.
You need to make sure that you're following the 301 redirects as that is not the final file location, hence why the data returned is only 957 bytes.
From looking at "upload.js" you are using AES in counter mode.
var aesCtr = new aesjs.ModeOfOperation.ctr(encryptionKeyBytes, new aesjs.Counter(-1));
Please use https://github.com/bitwiseshiftleft/sjcl which supports a very high-level sjcl.encrypt(passphrase, plaintext) API and has been audited, instead of using crypto primitives.
One specific issue is you are only encrypting, not authenticating, so if the servers are compromised someone could send back a fake plaintext.
Re authentication: the site uses HTTPS, and doesn't HTTPS provide authentication that you are connected to the right server, receiving only data from that server (assuming the server and it's contents aren't compromised)? Or are you referring to another type of authentication
> if the servers are compromised someone could send back a fake plaintext.
The server is sending the JS responsible for doing the encryption, no? If the server is compromised, all bets are off. You must trust this third party with your (unencrypted) data, unless you verify the JavaScript each and every time.
AES-CTR is indeed what's currently being used.
SJCL is definitely an option and we will compare the two to see if there are any large advantages to switching over, thank you for your suggestion.
The reason to why the content isn't being authenticated is due to memory issues in the browser, but we're close to adding a solution for that as well.
Overall the encryption feature is currently in BETA and there will be large amount of improvements before it's finalized.
I liked the service but I'm afraid it will end up like all the 1-click-hosters: as a storage for pirated content, blacklisted in most corporate networks.
Few comments:
Animated backgroud is very distracting. I'm constantly reacting to the new icons floating into the screen.
Underlined "Or" in "Click Here Or Drag & Drop To Start Uploading" makes me think it's some kind of a link. Any reason to underline it?
If I upload multiple files (which worked well) I want to be able to copy all the URLs at once. Displaying them in a text box would be good.
The reasons to why NoFile won't become a storage site for pirated content is that uploaders aren't rewarded for downloads.
"Animated backgroud is very distracting. I'm constantly reacting to the new icons floating into the screen."
Another user pointed this out and a toggle for the animations will be added to the settings so that you can turn them off.
'Underlined "Or" in "Click Here Or Drag & Drop To Start Uploading" makes me think it's some kind of a link. Any reason to underline it?'
It's underlined just to separate the two options (clicking and dragging) for those who just read the "Click Here" part and assume that the rest of the sentence is just a description to why they should click here (e.g "Click here to start uploading your file").
"If I upload multiple files (which worked well) I want to be able to copy all the URLs at once. Displaying them in a text box would be good."
Instead of a text box there could be checkboxes next to each file allowing you to copy URLs and delete files in bulk. We'll work on adding this as soon as possible, thanks for your suggestion.
There are plenty of sites not offering rewards that get used for piracy. There are other ways to monetize, and many pirates don't do it for money anyway. Don't expect that to keep pirates away.
> The reasons to why NoFile won't become a storage site for pirated content is that uploaders aren't rewarded for downloads.
This is a very very naive view of the situation. You're allowing user A to upload content which can be downloaded by an infinite(?) number of other users they give the link to. Therefore it will be used for piracy. And worse.
Edit: actually, a free unmonetized file hosting site? In this day and age? Behind whoisguard and cloudflare? Ideal law enforcement honeytrap tbh.
This guy gets it. But hey if the NSA wants to provide free hosting that is private and secure -- or apparently so until the drones level your neighborhood -- that's fine.
So who do you think actually will use this site and for what? For pirated content there are tons of free torrent sites. For legit content Google Drive, Dropbox and many others offer very generous free to use packages. Why would I ever use a file sharing site like this instead?
Console gets spammed with "not active or paused - skipping speed" messages, what are these?
There seems to be an onclose-like handler which warns me that I might have not saved the changes (I've uploaded 6 files). Do I need to "save" somehow? I see no "Save" button, nothing similar.
"not active or paused - skipping speed" is sent from the upload speed and estimated time measurement function and won't affect your upload.
The warning message that you receive when trying to close the page is only there to prevent accidental exits and in case you're in the middle of an upload or if you haven't copied the URLs of the uploaded files.
Unfortunately browsers no longer allow you to change the warning message, hence why it's telling you to save.
There isn't currently an app, but there shouldn't be any disadvantages between using the site.
You can upload as many files as you wish and save them on your phone to play offline (similar to what an app would do in the background) or play them directly from the site.
192 comments
[ 3.4 ms ] story [ 262 ms ] threadAll those useful features have been added to NoFile and made available for anyone who wants to use it - all free from ads, registrations, payments and it respects your privacy. Here are some of the current features (more to come):
* Simple upload process compatible with nearly all devices - accepts files as large as 10 GB to be uploaded
* Upload & download files without Javascript enabled (nearly all features are still available, although the site runs smoother with Javascript enabled)
* Password protect files (hashed with SHA256)
* Ability to encrypt files with AES-128 on the client-side before uploading to the server for secure storage (BETA)
* Easily view the metadata of a file (file type, dimensions, upload date, size, etc.) on its download page (URL to a live demo below)
* Preview files (PDF viewer, video/image/audio previews) before downloading (see demo URL below)
* All transfers are made securely over HTTPS to prevent malicious users from viewing what you're downloading/uploading (forced SSL)
* Securely view your upload history without having to create an account (history is stored in your browser's local storage)
* Save files directly to Dropbox (Dropbox scripts are only loaded when button is pressed to protect your privacy)
* No tracking codes and no third-party CDNs are used for external scripts, CSS or fonts in order to protect your privacy
---
Here are a few demos
- Download pages
https://nofile.io/f/BJ6MyXboYLj (an image with its preview enabled)
https://nofile.io/f/UH58eLI68Cl (an image with its preview disabled by the uploader)
https://nofile.io/f/Yl4NcFvsliN (an image with password protection - password is 12345)
https://nofile.io/f/OoG2wQwS33R#c725690e45b3a393 (an image encrypted with AES-128, secret key is stored securely after the '#' and not transmitted over the HTTP protocol)
- Upload completed page
https://nofile.io/edit/?id=UH58eLI68Cl&key=w69gz2D5y0RoH9umu...
To start uploading your own file(s) within seconds (without signing up): https://nofile.io If you have suggestions, a complaint or any features that you would like to see added then feel free to leave a comment or use this contact form: https://nofile.io/contact/"
Imho, if you really want to be the "Google of file-sharing", then the UI should be a lot less distracting.
Perhaps it would be useful to add an option that toggles the animations on/off.
If hundreds of people are telling you the animations are too much, kill the animations.
If a small handful of people are saying it, ignore them.
But please, please, do not add _any_ complexity to a small-margin, intentionally simple service like this in the hopes of pleasing everybody.
When you upload the same file it warn. Good enough. But when you continue anyway the KB/s and ETA displays do not show anything.
How can I view my history? I think I've clicked every link available but I can't find this at all.
I do see some data in my localstorage. I'm not expected to fish it out myself from there am i..?
> You can set an expiry time by pressing the "Options"-button that's next to your uploaded file
Same for this. There is no such option to be found. Screenshot: https://www.NoFile.io/f/FHA0M03bmm0#057e7d69b089e719
Also, I tried downloading my own screenshot but nothing actually happens. (The loader does pop up) Downloading & preview does work for an unencrypted file.
Firefox 51.0.1 (64-bit)
The button had been hidden for some users due to a bug. It's been fixed and you will be able to see it after refreshing the page, thanks for pointing it out.
"Same for this. There is no such option to be found."
This feature was disabled shortly after the launch due to a bug. It'll be added again as soon as possible.
The main difference is that nearly all of these hosts specialize in a specific type of storage. As an example MEGA forces all users to client-side encrypt files before uploading which is useful for sensitive files, but it comes with the cost of incompatibilities with older browsers and devices which can't decrypt/download the files.
Uploaded provides lots of space for the uploaders, but then pushes all users to its premium plan. The site is ridiculously slow to use as a free user as they cap download speeds to 50 KB/s (they bump it up to a 70 KB/s if you take the time to sign-up).
NoFile bundles all the perks of the different hosts and gives the user more options and fewer limits. You can upload large files and choose whether you want to password protect, encrypt or disable previews for your file while still giving the downloaders speeds of at least 2 MB/s.
It's just a simple file host that allows you to share files without having to worry about the downloaders being infected with a virus, not being able to download
What's your business model?
At the moment there is no revenue source. As costs for the hosting go up, there will be a more "humane" premium plan added in the future, but it will targeted to very frequent users and as a free users you won't be affected by the changes.
How do you want to keep DMCA claims at bay?
If a valid DMCA request is sent in together with a link then we will be forced to respect the content creator and take the link down.
Does this work mobile?
This works on every single device regardless of whether you have Javascript enabled or not. If you however enable the client-side encryption feature (currently in BETA) which is disabled by default then users on older browsers and devices won't be able to download your file.
So what makes you think your fate will be any different than that of all the other free file hosts that have had to resort to advertising in order to survive?
I don't mean to be negative, it's just that I've seen the transition from free to freemium to ad-supported to Rapidshare to dead happen over and over again. These services don't seem to operate with large margins - from the outside, it looks more like all of them are on the brink of bankruptcy.
Lets imagine our average citizen uploads quarter of a gigabyte, that means 4,000 visitors uploading files per $10 client. Assuming you can keep other costs really low, it's not too outrageously expensive.
Rapidshare was a service that had to swiftly and reluctantly change their business model. They were operating out of large offices with over 60 employees and due to the change they saw a sudden drstic drop in revenue.
Rapidshare's financial information isn't public since it's a private company, but one could argue whether they were actually losing money or not making the profits that they expected at the time of the shutdown.
Then came the FBI raid against various filehosts. I remember few of the other hosts got taken down and charged, while others shut their site down as precaution. I remember Rapidshare starting their decline during this phase, something tells me Rapidshare did it on purpose and 'ran away' with the earned money before the feds got them.
Well thats my theory :)
In plain-English, what does this mean?
The most concerning aspect of your model is charging users for download speed. That might cause users to pay you, but it puts an incentive on business to host questionable content. Megaupload and Rapidshare were doing the same thing.
Protect sensitive files with encryption. Only users with the URL will be able to view it. "
This is not encryption - you should change the copy to tell what encryption is used (AES-128 from the info here), even if it's beta. Some more information on that will be welcome.
A link has also been added to that block to make it easier to find, thanks for pointing it out.
"Your file is first securely encrypted using a secret key (AES-128) with Javascript on your device. Once it has been encrypted, the encrypted data is uploaded to a NoFile storage server over a secure HTTPS connection preventing any malicious users from seeing what you're uploading (as an extra layer of security).
Only those with the secret key (which is in the URL) will be able to see the correct content and filename - if a single character of the key varies, then the file will be unrecognizable."
You need to set this as your preferred method on the upload page.
CTRL+F finds no other asterisk on the page, what's the caveat?
Also tonnes of decent ad supported options with no crap like wait time and million popups like Openload Zippyshare AFH
(oh and site looks & performs great! Best of luck for future)
Did you mean to infer that MediaFire was less crappy than this showcased one? Or crappier than this one? Your follow up sentence would indicate the latter.
OP's site looks great!
The problem being that you have to jump between different hosts depending on how large your files are and which features that you want to use (e.g Mediafire for larger files, Zippyshare from public PCs so you don't have to login, MEGA for sensitive files that you want to send securely, Dropbox when you don't want grandma's PC to get infected when you're sending her the videos from Christmas).
The goal is to create one single host that saves you from having to jump from each host and having to maintain dozens of accounts to bypass limits.
Question - would you, in the future allow uploading to configurable destinations, e.g. my own S3 buckets? Also, do you track the number of time a file asset was downloaded from your service so that the original uploader can check activity stats?
EDIT: Feedback - when I scrolled to the bottom of the home page, the "There is something I have to tell you" section is duplicated under itself.
Right now there's only an option to upload files to Dropbox, but the plan is to add as many useful alternatives as possible and S3 would be a good option.
The number of times a file was downloaded is currently being counted, but it isn't public. It would be an interesting idea to display it on every download page by default (similar to Imgur) and give the uploader the option of disabling it.
The duplicated info block has also been replaced, thanks for pointing it out.
> As long as possible
What a stupid answer to that question! (it gives more info - "You can set an expiry time by pressing the "Options"-button that's next to your uploaded file, otherwise your files will float in the clouds for as long as possible." - but it still doesn't really give any answer)
In all likelihood, the internet itself might evolve into something different in that time. This service might get bought out, or shut down, or the original founders may (fate forbid) get hit by a bus next week.
Setting any sort of indefinite limit is opening themselves up for legal action if it is even one minute less than someone expects. "As long as possible" at least is honest enough to say that as long as there is enough interest to keep the lights on, they will be there.
What makes you think that ? It may be days, where "as long as possible is "we hope to keep the files a few weeks".
Without some sort of project plan you don't know if NoFile.io is aiming at snapchat for file, or S3 for everyday Joe.
Without some sort of guarantee of availability, I wouldn't be able to recommend it to friends, coworkers, or family. I don't want to advertise something that is truly a great service but ends up shutting down few months from now after people start abusing it.
But if the site does decide to shut down then we will be sure to notify users about this at least a month in advance in order to have time to make backups.
"Hmm, this looks pretty... what is it for?
It has a huge area that says "click here or drag and drop to start uploading"... but uploading what? And why?
Let's scroll down and read the 'about'!: "Fast", "Compatible", "Encryption"... um... ok but WHY?! Is it personal file storage for me (Like Dropbox?) or is it like a public FTP server? Or something else? If I drag and drop my tax return there is it suddenly shared with the entire world? Why do I want this thing?! Back to the HN comments to find out more!"
Something like that anyway! According to the comments it seems to be more like a rapidshare/mega thing - and now that I get it I'll keep this site in mind for sure!
The upload box is the first and almost only thing that you see when you go to the page and the purpose is to make the process simple so that you don't have to click through to a second page in order to start uploading.
You do however have a point as it could be confusing for some new user who haven't uploaded files before. We'll try to add an info box or some additional text to make the message more clear, thanks for pointing it out.
Localhostr was great for a while for just uploading stuff without needing to bother with accounts or RapidShare's wait-a-minute-or-pay thing. It makes sense why you scaled back the free version (I can imagine that these services quickly get expensive to run..) and started requiring accounts. But personally that's the point where it was roughly equally annoying to upload to Hostr and my own server, and so the latter just made more sense for me personally.
- How active the file is (e.g if the file isn't downloaded in X days).
- How much space that's available on the storage servers.
As mentioned in a previous comment, the site's operating on small margins so the majority of the income will go to expanding the storage in order to make sure that your file is never deleted (unless you request).
At the current rate your file would never be deleted (again, unless you request it) and at a bare minimum your file will be stored for at least a week without downloads so you don't have to worry about your file being deleted before your downloaders get to it.
This will be updated in the FAQ section to avoid confusion as well, thanks for pointing it out.
I'd like to challenge you on the site name, though. Why'd you pick it? If I'm a normal user who stumbled across the site, I might be confused if a site called "NoFile" wanted me to upload files.
http://i.imgur.com/IEHrxm7.png
https://nofile.io/f/KrLDHQyKt4J
You should now be able to see your own PDF instead of a placeholder, thanks for pointing it out.
Edit: also, password protection is enforced server side, and has nothing to do with encryption
The password encryption is indeed server-side, but it is mainly there to protect the file against anyone who somehow finds/guesses the URL and it's a useful feature if you want to slightly increase the level of security without encrypting the file with AES.
That is incorrect. Knowing the hash does not mean you know the contents of the file. You should generate encryption keys randomly, preferably using a secure random method such as that shipped with SJCL, rather than JavaScript's random API.
Random strings and numbers are also securely generated through a CSRPNG with window.crypto.getRandomValues().
Feedback: the navigation bar at the top is quite unusable from an UE point of view. The positions of the icons (and therefore the hovering position) change as the mouse hovers them. It is quite annoying.
Also, in the FAQ: "How can this be a free service? Magic" This sounds to me as: "stfu, don't ask, you are not clever enough to understand" or "there is some dirty way to get money from you, better don't ask".
The following phrase made me feel a little uncomfortable about using the product.
"How can this be a free service? Magic. In the future a paid service will be introduced offering more awesome features, but don't worry it shouldn't affect the free service."
I'd rephrase this - definitely remove the shouldn't as that tells me that while my files shouldn't be deleted, they might be.
Finally, just a minor thing, but the down arrow under the "Click Here Or Drag & Drop To Start Uploading" doesn't work for me (latest Chrome on Mac). I assume it should scroll down the page but it didn't for me at least.
NoFile is a simple tool that allows you to quickly share files with lots of options, nearly no limitations and at the same time as you don't have to sign in.
"I'd rephrase this - definitely remove the shouldn't as that tells me that while my files shouldn't be deleted, they might be."
You're right about that as the premium plan will never lead to files uploaded by free users to be deleted. The premium plan will only be targeted to more heavy users and won't affect the free users.
"Finally, just a minor thing, but the down arrow under the "Click Here Or Drag & Drop To Start Uploading" doesn't work for me (latest Chrome on Mac). I assume it should scroll down the page but it didn't for me at least."
The button was indeed not working and it's now been fixed, thanks for pointing it out.
put that on the top of your page!
One specific issue is you are only encrypting, not authenticating, so if the servers are compromised someone could send back a fake plaintext.
That's the assumption that file authentication would remove. Well, assuming that the server isn't also sending a backdoored client..
The server is sending the JS responsible for doing the encryption, no? If the server is compromised, all bets are off. You must trust this third party with your (unencrypted) data, unless you verify the JavaScript each and every time.
The reason to why the content isn't being authenticated is due to memory issues in the browser, but we're close to adding a solution for that as well.
Overall the encryption feature is currently in BETA and there will be large amount of improvements before it's finalized.
Few comments:
Animated backgroud is very distracting. I'm constantly reacting to the new icons floating into the screen.
Underlined "Or" in "Click Here Or Drag & Drop To Start Uploading" makes me think it's some kind of a link. Any reason to underline it?
If I upload multiple files (which worked well) I want to be able to copy all the URLs at once. Displaying them in a text box would be good.
"Animated backgroud is very distracting. I'm constantly reacting to the new icons floating into the screen."
Another user pointed this out and a toggle for the animations will be added to the settings so that you can turn them off.
'Underlined "Or" in "Click Here Or Drag & Drop To Start Uploading" makes me think it's some kind of a link. Any reason to underline it?'
It's underlined just to separate the two options (clicking and dragging) for those who just read the "Click Here" part and assume that the rest of the sentence is just a description to why they should click here (e.g "Click here to start uploading your file").
"If I upload multiple files (which worked well) I want to be able to copy all the URLs at once. Displaying them in a text box would be good."
Instead of a text box there could be checkboxes next to each file allowing you to copy URLs and delete files in bulk. We'll work on adding this as soon as possible, thanks for your suggestion.
This is a very very naive view of the situation. You're allowing user A to upload content which can be downloaded by an infinite(?) number of other users they give the link to. Therefore it will be used for piracy. And worse.
Edit: actually, a free unmonetized file hosting site? In this day and age? Behind whoisguard and cloudflare? Ideal law enforcement honeytrap tbh.
Console gets spammed with "not active or paused - skipping speed" messages, what are these?
There seems to be an onclose-like handler which warns me that I might have not saved the changes (I've uploaded 6 files). Do I need to "save" somehow? I see no "Save" button, nothing similar.
The warning message that you receive when trying to close the page is only there to prevent accidental exits and in case you're in the middle of an upload or if you haven't copied the URLs of the uploaded files.
Unfortunately browsers no longer allow you to change the warning message, hence why it's telling you to save.
As mentioned in a previous comment, since uploaders aren't rewarded for downloads this shouldn't become too big of an issue to handle.
Tried to upload a 9.66 GB test file but am getting following error message
"File Size Limit This file is too large. The largest file size that can be uploaded is 1.25 GB"
What am I doing wrong?
It's been changed and you can now upload files up to 10.2 GB, thanks for pointing it out.
Is there any other options other than dropbox?
You can upload as many files as you wish and save them on your phone to play offline (similar to what an app would do in the background) or play them directly from the site.