HN user

ldubost

66 karma

Founder and CEO of XWiki

Posts10
Comments39
View on HN

True.. Now for "first value" we have "create a pad in one click to work with your friends", also 1gb data for free.

There is Google Takout + Folder import to do mass imports.

There is work possible to improve but also through the browser it's tricky to make large volume imports reliable. Best path is an API which would also allow backup tools and down the line local syncing.

Overall for people wanting more of CrytpPad, think about donating on OpenCollective https://OpenCollective.com/cryptpad

Ludovic from the CryptPad Team

Drive might be 'useless' to you in it's form because you want more from CryptPad (more features in it, more local sync, more anything), but it is very useful to organize your docs that you work on in CryptPad. It also allows shared folders and so on.

What's interesting is that surveying our users did not show local sync as hugely demanded. Mobile access comes up the highest.

We do believe having an API is valuable and a good selling point. It's also a great way to get an ecosystem to help us extend the product. Now it's also more responsibility to maintain compatibility. We want to be able to continue to upgrade services (in particularly cryptpad.fr). Apps using the API would need to continue to function or by security be locked out. This is a lot more work for the small team.

Ludovic from the CryptPad team

We never pretended the drive has local syncing. The drive is extremely useful for people to organize their documents inside CryptPad.

It is possible to create folders with any file types in it. Shared folders can be also created.

The workflow you describe with syncthing involves local synching.

We are not saying that syncing locally is not interesting. It's just a lot more work on top of the editor work, the online sharing, the e2ee, etc.. We work with the capacity we have. Also as I said, syncing opens the door to version compatibility issues, risks of mistakenly deleting data of your drive and high volume just for storage. This means for our hosting service (cryptpad.fr) management of much higher volumes. We are not even sure the 1gb free storage policy is sustainable for that use case. But we are working on a path towards this as we have plans for a CryptPad API.

Ludovic, from the CryptPad team

Hi,

We have started work on this through sponsoring of openDesk: https://apps.nextcloud.com/apps/openincryptpad This allows editing of diagrams stores in Nextcloud using cryptpad. However the files are not e2ee in Nextcloud.

The API we build has now been extended to other file types and also support e2ee https://github.com/cryptpad/cryptpad-api-examples

Integration with the new web version of e2ee of Nextcloud could be possible now but we don't have capacity to develop this. Integration with other e2ee tools is also technically feasible.

What type of integration are you looking for ? We would be interested to understand the workflow you would find interesting.

Ludovic, from the CryptPad team

The choice depends of what you use and how you use Google Drive.

Nextcloud is great. It has the highest coverage towards the Google suite without e2ee.

I believe we at CryptPad have the highest with e2ee. If you go cloud e2ee is an important privacy and security factor.

If you self host it can also be depending on how you are able to protect your server.

CryptPad is more scoped around editing documents. I believe it's a simpler package around the pure google docs functionnality.

Nextcloud is better for storing many docs, photos etc.. And has file sync to your computer and a mobile app.

We don't have comparisons.. But maybe we should.

Here is an independent review of CryptPad: https://www.privacyguides.org/articles/2025/02/07/cryptpad-r...

"Signal has sacrificed ease of use in favour of security by refusing to release a web app for some time.. they're doing pretty OK in terms of number of users. I think it's also fine to choose a different balance and favour ease of use more, but concessions to security based on your team's priorities should at least be acknowledged."

Again you mention Signal, a org bootstrapoed with a promise of 100m$ and way more funding than us. They have apps for iOS, Android, Linux, Mac, Windows. Are you realizing the comparison you do ?

You say our concessions to security should be acknowledged. Check our white paper.. We do mention code hacking on the server. When did we say we protect you from your computer setup ?

You want us to warn users about links more visibly. Fine, make reasonable proposals ?

You want us to make desktop apps.. We want that too.. We tell you it does not fully solve the issues you mention.

You want us to drop web apps like Signal who does not do that. We tell you this would kill CryptPad.

Yes the way you overstate the issue instead of telling activist to run their own servers, with a browser they control on an OS they control, is indeed hurting. You mention users are not knowledgeable. This FUD reduces the trust in our work. Sure I understand you are trying awareness.. Which for us ends up being social pressure.

Open Source is simple.. Don't complain, code... Contribute...

Ludovic

Disclaimer: I'm the CEO of the company doing CryptPad.

The problem I have, is that you say the word "vulnerability" for CryptPad when we never promised to protect you from a badly configured computer.

If there is a vulnerability, it's unsecured browser syncing which would be exposing your browsing history to Google. Google Docs has anonymous links which are in that history too.

BTW I could not find any info about browser companies exposing the synced browser history. As far as I know It's encrypted on Chrome and Firefox. But maybe I'm wrong as I believe if people want to be sure why would they use browser sync ?

Note that in addition to passwords there are also Access configs where the server can block access to documents to specific users. This is an additional security which mitigates the issue of links that would be opened on a bad browser. Sharing links through CryptPad as also the recommended way to never have URLs opened by your browser.

When I mentioned PR, you could also fork and run your server with higher security settings.

If a team does not respond to your vision, you can indeed bitch about that team, or you can come and give more proof of your vision. Documentation also help ? Why not document that browser syncing would be risky for activists ?

So take this as a call to be constructive. Make a github issue and propose something that helps. Maybe indeed add a message and a link to more documentation about good and bad ways to use shared links.

About "> empower laypeople to collaborate on documents with reasonable confidence that nation-state actors won't be able to passively surveil those documents", did you read our white paper ?

Ludovic

I'm from the CryptPad Team.

We did not use this sentence. It's the person that posted this that wrote 'Google'

However we believe CryptPad can be part of the solution for both Google and Microsoft

Now the targets are different. Google has most of individuals and B2C. Microsoft is more the larger companies

At this point CryptPad seems to have more tracking on the individual market.

For companies, there are different approches like self-hosting. E2EE in companies is a niche market for which collaborative editing is new.

So 'Google' as an exit-target is probably yo the right goal

We have started working on that.

The load time currently depends on the size of your drive/share folders etc..

Public links are now bypassing some actions. We hope to bypass more in the future

Ludovic

Your last paragraph is quite insulting to the work we do, suggesting intention to trap people ? Did I read this right ?

I'm not really sure i want to continue the conversation unless you retract this. Our team is working hard on many fronts and does not deserve to be treated like that.

If you believe it's critical that the "link situation" be resolved, where is the pull request, or even the specification of the necessary change ?

Ludovic

It might have been a long time ago because we have invitation links in teams:

https://forum.cryptpad.org/d/5-improve-onboarding-for-teams

We even implemented links that can be used multiple times before an expiration date.

Concerning the privacy of emails, YOU had the emails, but the SERVER ADMIN does not.. To send an email from the server, the server would need to receive the emails in clear.

As a side note, when you invite somebody to a service by letting the service send the email, you are leaking their email to that service, so to be respectful of people's privacy, we should not send the invite without their consent receive first. I get that nobody does that and there is a sort of implicit consent and that the risks of misuse of the email ate low.. If we ever implement that feature we would have to show a warning.

Ludovic

I'm from the CryptPad team

This workflow works for you ! Great !

Unfortunately, most users don't know how to setup the tools you are talking about. Additionally they end up having to share some document at some point or another. They end up with browser based tools and a shared server. Google most of the time for individuals. Most users want their data in one place for all use cases.

Network effects make it so that only tools that allow you to invite anybody to your document (guests without accounts included) end up gaining traction. Desktop apps might be able to achieve this using some web proxy so who knows, it might change in the future.

Our goal at CryptPas is to make it familiar for them to move from Google while having e2ee here to protect their privacy, which also gives them a reason to switch

The more people can get out, to any open alternative, the more alternatives can then decide to fight each other.

In the mean time, we should not try too much to get the rest of the world on our own workflow, just let all the different approaches strive.

BTW maybe CryptPad's API ( https://github.com/cryptpad/cryptpad-api-examples ) could help you solve the case where you do need to edit a document collaboratively from your computer. Would you be interested in a tool allowing to create a session for editing with CryptPad allowing to sync back changes or save the end result back to your computer ?

Ludovic

I'm from the CryptPad team.

We hope to be able to give an API in the future but there are a few concerns to allow sync tools to operate:

- server load and volume of data when syncing large volumes of data, especially for our flagship instance. CryptPad is currently used for realtime editing not for large data sync. We already host 6TB of data and it's unclear were that would lead us. - version compatibility with apps not upgraded to the latest version of the API

These are similar reasons that kept us away from federation.

Our team is small and already a lot of work. Hiring is limited by our funding.

Ludovic

I'm the CEO of the company developing CryptPad.

Our main promise to our users is that server operators cannot read the users data.

About code alteration attacks, we have mentioned them here in an article exposing ways to use CryptPad in secure ways https://blog.cryptpad.org/2024/03/14/Most-Secure-CryptPad-Us...

I won't respond in detail, at least today, to all your criticism of our work but I will say two things:

CryptPad might not be at the level of privacy or security you want (which one do you want BTW ?), but with such discourse you are sending users to stay handling their data on Google which seems to be the opposite of what you seem to want. We will of course consider on our end that CryptPad greatly enhances privacy and security compared to the situation where everybody's data is in clear at Google or Microsoft.

You mentioned " I did share all of the above with the CryptPad team, and was told they don't intend to address the above issues". If you can dig out our response it would be helpful ? At least my position as CEO is that we intend to solve the issues we can solve with the funding we have. As an example, we have always been interested in finding a solution to the "code attack". However the desktop app or code signing does not fully solve the issue as you still need to trust who builds the desktop app or signs the code, even when signed. Full trust requires audit of the code at every change. Can you name me one app that you can fully trust ? Have you audited it ?

I'm not saying improvements cannot be done and we'd love to do a desktop app but we have to choose our battles. We would still have to see if people install and use it ? Signal is a mobile app.. How many have it on their computer ? How many use slack instead ? (When a billionaire gives 100M$ to CrytpPad, we'll be happy to have our choices challenged compared to those of Signal). If one is listening our OpenCollective is here https://OpenCollective.com/cryptpad

We'd love to do more both for privacy and security and ease of use, but for that we need more funding.

Our belief is that privacy and security will be won again on the Internet step by step by getting users to any non BigTech tools including CryptPad and then improve them step by step. If we have the users, we have higher chances to have the funding to improve the tools.

Your vision seems to be more extreme and would likely fail to bring anybody to such a platform as it would lack ease of use (at least with the level of funding we have).

Until now, your criticism is not helping getting the users out of Google or Microsoft.

Ludovic, CEO of XWiki SAS

I'm from the CryptPad team.

It would not really make any sense to try to take all Docs in CryptPad, as Docs is both client and server code. The client has both and editor but also sharing features.

CryptPad integrates editors.

However Docs is based on BlockNote for the editor and this editor has been on our watchlist to replace our aging CKEditor which is used in CryptPad. This would make sense to integrate in CryptPad.

As it was said CryptPad is e2ee which is a LOT of work. Then it has 9 types of document files (Docs has 1). CryptPad also has a drive. It also has shared folders, team drives, import and export features and finally also a Survey Tools with e2ee protection. There are many more little or larger details.

Ludovic

Hi,

I'm from the CryptPad team.

This is an interesting feedback.

Note that you can also invite people by sending them a link to a document and then connect to them from the user sidebar. They don't really need an account to access documents.

The main reason for the lack of simpler invitation using email is that we don't really want users to give us the mail of other users to invite. This goes against the "privacy" we are promising users.

Ludovic

You are right that there is a difference between products and libs and it seems difficult to get donations or yearly support for libs. Good that it's meant to be another option. I'd like to say that service has helped me get XWiki off the ground, for a product too, but that while you do it you need to have in mind "how to I make the product sustainable with recurrent revenue".

For libs, I believe what you need to think about is who the lib maintaners are and in what context do they do it ? How many are freelancers ? How many employed ?

One thing that you could do in your service is to allow for links to donations and maybe chip in extra in the service costs even if it's not demanded. I still think that the donation market can expand with open source funds. At XWiki we have a fund (for which we have a hard time completing the work of project sélection). One thing we miss most is knowing which projects really need to donations.

As you say, it's hard to get the superiors to even give a donation. However if you can mask the donation in some "needed service" it can work. At XWiki we created open source extensions which are paying (not packaged for free). I'm not sure for libs it work though.

If you are interested in how we got XWiki off the ground and funded, I had a fosdem talk about it. There are slides and video here: https://fosdem.org/2024/schedule/event/fosdem-2024-1830-20-y...

Based on a long experience making open source for a living (I created XWiki, an open source wiki), I think it's though to finance OSS using time based support, at least using usual consulting rate. Either it needs to be understood by clients that the rates should be very high, or have different rates for time based paid contributions versus consulting. Maybe some option could be also to allow paid support by non committers provided they share revenue with the maintainer. If the project is sufficiently popular this could finance maintainers. The maintainer could still provide consulting but at a higher rate. There could also be a special rate for "faster" support, or even a retainer.

Ideally to help sustainability, creators need some fixed yearly support, but while this works for products, it's difficult for libraries.

What is sure is that it's important to bring some margin to the maintainer so he can fund his work.

The short answer is "yes" but it's nothing but easy.

SaaS or paying versions (whether the extra features are open source or not) are possible financing sources.

However SaaS requires specific investments which don't finance the open source software itself and you need to factor them in.

As you say, people can self host so you have a "competitor" for your offering. One way to handle this is to have the same free tier in your SaaS than in your self hosting and you can provide paying versions also on the self hosting. Note that you can do paying version that is open source. At XWiki (xwiki.org xwiki.com) we do this with our Apps Store and paying extensions, but all our extensions are Open Source but not deployed for free. This shows our commitment to Open Source. We show to the community that we need ways to pay, but we also show that we are not trying to close down the projection or refuse collaboration and competition with our community.

You could also not have a free tier or smaller tier on SaaS and concentrate on the easy of getting the full service running and ready to go. Now a significant part of open source users are here for the self hosting and keep control. Others are also in for getting things for free (either because they like free, or their boss likes free, or even because buying is complicated). But these free users are also your marketing. Never forget that when you try to get some revenue. It's easy to turn back on your community. In the end you need the free users to prove the project and if you make all paying the reach is reduced. From my pov, the goal is to create more Open Source, not more revenue. The revenue is there to make more Open Source.

So in the end, the paying users will always be a small percentage of you free users. It can be 1% percent. Could be more or less depending on the type of users or software. On SaaS with individuals same rules as free tier that's not open source can apply and be even less.

Now the key is also to have great software. More happy free users, more paying ones.. Same for donations.

But if you start asking for money, whichever method, it's good to be transparent about it. How much money is made, how.. What do you do for it. For example in one comment, somebody mentioned donations going down when launching a service. This can easily happen as users have not idea what's going behind the scenes, because they don't have the numbers. For cryptpad (cryptpad.org) we decided we should publish the numbers. It's not easy to keep it up to date as we work a lot to build the software, developer offers, find funding from projects and so on. But we try. See an example here: https://blog.cryptpad.org/2023/02/09/CryptPad-Funding-Status...

On the XWiki side, we would want to do it too, but lack time, and most of our funders are not companies, which are more interested on how competitive our offer is towards proprietary solutions, than how we fund it. This is also key in the end. Companies and Users have money. They just use it for what they really need and for that they will very often look for the best offer. As opensourcer you still have to convince that it's the best offer and most users won't really care about the fact that it's open source. We still have to convince them that Open Source is valuable in itself and that users should actually pay more for it..

Hope this helps.. Ludovic, XWiki and CryptPad

The Social Dilemma 6 years ago

So the dynamics have always existed in previous platforms, it's just been ratcheted up to a higher level with social media.

I remember a friend saying the "optimization is killing us". The whole economy is getting better at what it does and as it happens there are many side effects.

Those with no ethics will manage to harvest the social media technology for their profit and not for society. It applies also to taxes where companies are getting master at dodging them. Liers are getting masters at lying and we have to fight to rebuke the lies (the documentary has a quote about how much more effort is required to fight disinformation than to create it)

He also argues that optimization is poison to yourself ! But that's off subject.

The Social Dilemma 6 years ago

> "Changes to your behavior and actions..."

Isn't this the definition (or goal) of all advertising? I don't see the connection to the first half of the statement tying it to free products and services.

I believe it was "the product is the 'ability' to change your behavior"

So the difference here is that not only the sell it but it actually works because it can adapt to the people in realtime. This is probable what is scary..

Standard advertisement is already manipulation but it's more easy to know when it is advertisement (though it's arguable that there are also tricks to get around this for TV).

In my view it is indeed the advertisement industry going too far and being allowed anything. Social Media just build a product for its client and none of them have any doubt and limits when it comes to choosing between profits and ethics.

Advertisement is ok when it is honest and not manipulative.

In addition the product is sold for politics which is even more scary.

There are regulation in many countries about what's allowed or not in advertisement. In some cases it's not allowed to blatantly lie. Or it is not allowed to hide advertisement as content, etc...

It is possible to forbid micro-targetting and manipulative AI algorithms or other methods. Users & Regulators need to understand what is being done, and how the effects are harmful to society.