Skip to content
Add as Preferred Source

filen

2 posts with the tag "filen"

Filen vs Proton Drive: How Their End-to-End Encryption Differs

Filen and Proton Drive both encrypt your files on your device, so neither company can read what you store. People comparing them usually want to know where the designs actually differ, and whether switching is practical.

FilenProton Drive
File encryptionAES-256-GCM, done on your device[1]A session key per file, with OpenPGP keys (Curve25519) protecting the keys[2]
File names and metadataEncryptedEncrypted, so Proton cannot see names[3]
Tamper detectionAES-GCM is an authenticated mode, so a changed chunk fails to decryptSignatures on key passphrases and on a chain of block hashes, so a changed or reordered block is caught[4]
Open sourceAll apps, AGPL-3.0[5]Apps and encryption libraries[6]
Independent auditNone linked from Filen's about and security pagesReports published, Drive audited by Securitum[7]
Company and serversGermany, GDPR[8]Switzerland, outside EU and US jurisdiction[9]
Other toolsWebDAV and S3 only through a self-hosted CLI mirror; rclone backend[10]rclone backend rated Tier 4 and in beta[11]; Proton Drive CLI[12]

Filen's model is the simpler one to describe. Contents are encrypted with AES-256 in GCM mode on your device, and the key material is protected by your password. Filen's pages describe the cipher and the open source clients, and leave the key layout to the code.

Proton builds on OpenPGP. Each file and folder gets its own key pair, and the passphrase for each is encrypted with the key of the folder above it, up to a share key that your account key unlocks. File contents use one session key per file. Every passphrase is signed with your key, and so is the chain of block hashes, so a compromised server cannot forge or reorder content without detection[13].

The practical effect shows up in sharing. Because Proton wraps keys with public-key cryptography, adding a person means encrypting one key again for them, and the file itself is untouched.

  • Audits. Proton publishes third-party audit reports. Filen invites you to read its code, and its pages do not link an audit report. If an independent audit matters to you, check Filen's current status before deciding
  • Jurisdiction. Both are inside strong privacy regimes. Germany follows EU law and GDPR. Switzerland sits outside the EU and cites its own protections
  • Ecosystem. Proton Drive comes with Mail, Pass and the rest of the Proton account. Filen is storage-first, with sync, notes and chat inside the same app
  • Getting data out. Neither can hand your files to another service, because neither can read them. Both need a tool that decrypts on your computer

Neither provider can copy your files to the other, and the keys do not transfer. A move has to decrypt each file on your computer, then encrypt it again with the destination's keys.

Blober does this in one workflow. Sign in to each provider through its own login page, pick the files, and run the transfer. The Filen setup guide and the Proton Drive setup guide cover the sign-in steps. Neither password is stored by Blober.

Which one is more private? Both hide file contents and names from the provider. The differences are the legal setting and how much outside verification each has, covered above.

Is AES-256-GCM weaker than OpenPGP? No. They do different jobs. AES-GCM is a cipher, and OpenPGP is a format that also covers key management and signatures. Proton's files are still encrypted with a symmetric session key. The difference is how keys are wrapped, shared and signed.

Can I move my files from Filen to Proton Drive in one step? Yes. Blober reads from Filen, decrypts on your computer, and writes to Proton Drive, which encrypts them again. You do not export or re-import anything by hand.

Will my folder structure survive the move? Yes. Folders and file names carry over, and a path template can reorganize them on the way.

What happens to shared links and sharing settings? Blober moves files, not sharing settings. Sharing is tied to each provider's keys, so recreate links and shares at the destination.

What if I lose my password? Neither company can read your files, so a lost password can mean lost data. Set up the recovery option your provider offers before you rely on it.

Move files between Filen, Proton Drive and 20+ other providers in one workflow. Blober runs on Windows, macOS and Linux.

Download Blober at blober.io

How to Back Up Filen (or Move Files Out) Without the CLI

Filen encrypts your files on your device before they upload, and its servers never hold the keys. That protects your privacy, and it also means no other service can simply fetch your files. Any backup or migration out of Filen has to decrypt the files somewhere you control.

Why the usual routes go through the CLI

Section titled "Why the usual routes go through the CLI"

Filen's answer for other tools is the Filen CLI. With it you can:

  • run a WebDAV or S3 server on your own machine that mirrors your drive
  • export an API key for rclone

rclone's Filen backend, added in rclone 1.73, needs that exported key. You install the CLI, sign in, run export-api-key, then give rclone your email, password and key. If you change your Filen password, you export the key again and update the rclone config[1].

Filen is also retiring the CLI in favor of a Rust rewrite. The CLI README points users to version 0.0.36 for now[2].

The WebDAV and S3 servers run only while the CLI is running on your computer, so there is no hosted endpoint to point another tool at.

Threads on the rclone forum show the same trouble spots:

  • Setup fails at the first sign-in with a getMasterKeys error[3], or with "cipher: message authentication failed" while decrypting the master keys[4]
  • One user calls the setup "pretty confusing" and asks whether anyone has it working[5]
  • A 15 to 20 GiB single-file backup uploads at about 3 MiB/s when an rclone encryption layer sits on top of the Filen remote[6]

Blober connects to Filen directly, so there is no CLI to install and no server to keep running. Sign in once through Filen's own login page, with two-factor authentication if you use it, and Blober decrypts files on your computer as it reads them.

  • Back up Filen to a local folder, a NAS, or any other connected provider
  • Move files into Filen from another provider, encrypted as they upload
  • Re-run the same workflow whenever you want a fresh copy

To set it up, follow the Filen setup guide. Then pick Filen as the source (or destination) in a workflow, choose where the files should go, and start the task. A file that fails is retried without repeating the whole task.

Files leaving Filen are decrypted on your computer. If the destination also encrypts, such as Proton Drive, it encrypts them again with its own keys. A backup to local disk or a NAS is plain files, readable without Filen.

After a Filen password change you sign in to Blober again. The old session stops working.

Do I need the Filen CLI to use Blober with Filen? No. Blober signs in through the Filen login page and needs no CLI, API key export or local server.

Does Blober store my Filen password? No. You type it into Filen's own login page. See the setup guide for the steps.

Is the backup still encrypted? Only if the destination encrypts it. Files are decrypted when Blober reads them from Filen. A copy on local disk is plain files, so keep that drive protected.

Can Blober copy Filen files to another Filen account? Yes. Pick Filen as the source and as the destination, signing in to each account separately. The files pass through your computer and are encrypted again with the second account's keys.

What happens when I change my Filen password? The old session stops working. Click Open Filen Login and sign in again.

Are deleted files really gone? Deleting through Blober moves a file to the Filen trash. Empty the trash in Filen to remove it for good.

Back up Filen, or move your files out, without installing a CLI. Blober runs on Windows, macOS and Linux, and connects to 20+ providers.

Download Blober at blober.io