Nextcloud is designed to keep your data secure while you sync your data and work with other people. With every release, we bring new technologies, visible and invisible, to secure files and enhance collaboration. Nextcloud 14 introduces our innovative Video Verification and Signal & Telegram 2FA support for security. To enhance collaboration, we introduce note shares, search in the content of comments, recovery of deleted group shares and improved federation. This blog post aims to update you on these and other improvements.
HackerOne: paying experts to find issues
While we regularly get praise from customers who have done pentesting on our software, we believe that getting the help from the global security community is important to validate our security efforts. Our HackerOne program pays out money to hackers who find issues in our software and responsibly disclose those to our security team.
A recent HackerOne case study has analyzed our security work and concluded our bug bounty handling is an example for others to follow. Michiel Prins, co-founder HackerOne, had this to say:
Nextcloud’s lightning fast response times are impressive and make them a model for how to build an efficient bug bounty triage and response process.
You can learn more and download the case study from the HackerOne website.
New security features in Nextcloud 14
For Nextcloud 14, two main security features are new:
Video Verification
Signal/Telegram/SMS 2FA support
We also updated our SAML and Kerberos authentication and introduced a new GDPR compliance app.
Video Verification
Video Verification
Video Verification is our new, unique feature that is meant to ensure that only the right person looks at the data you shared. You might think: well, I put a password on it, won’t that do the trick? It is indeed true that a password for a share link, especially when sent through another channel like sms, makes it harder for a third party to get access to the files. But there are certainly scenarios where this still happens: a spouse might use the phone, or a child. For most data, this isn’t a big deal. But think of a doctor who wants to make sure an X-ray only can be seen by the patient, not their family?
Just like a bank might require you to physically come in to open a bank account and a doctor would require a visit to tell you the results of an examination, you might want to make sure some data strictly ends up before the intended recipient. This is where Video Verification comes in. When this option is enabled, the user receives only the share link, not the password. The share link page gives a ‘request password’ button, which starts a call using Nextcloud Talk. Your phone will ring and you will be able to see and talk to the intended recipient! Once you have verified who it is, you can give the password and he/she can log in and view the data.
The second main security feature in Nextcloud 14 is a new second factor authentication provider. 2-factor authentication improves the security of authentication by using a second way of ensuring only the right person can log in: besides a password, a code from a device like a phone has to be entered. New in this release is the ‘gateway’ 2-factor provider. It allows use of the secure messaging apps Signal and Telegram as well as various SMS gateways as a second factor to secure their authentication. Most up-to-date applications communicating with Nextcloud now use Login flow so you will be able to log in just like you would on the web, including, but not limited to SMS-based authentication. Absent support for the Login flow, your legacy applications will accept device passwords.
Note that especially the Signal authentication support relies on a third party docker container, so take some care with it. You can learn more on this page.
In other 2-factor news, the app now officially supports authentication via NFC (Yubikey NEO)!
SAML and Kerberos
Thanks to a collaboration with the TU Berlin it is now possible to authenticate to Samba servers while using Kerberos authentication. Note that this requires the server to already have a valid ticket to authenticate! The Nextcloud SAML app was updated with support for multiple Identity Providers, allowing a server to have both local users and SAML authentication. The SAML configuration was also simplified.
GPDR
When working with others, it is important to keep data not only secure but also within the legal boundaries set by compliance regulation. Nextcloud has made another step forward in this area. This release introduces a Data Protection Confirmation app and a separate audit log file, complementing to the existing Impressum/legal notice and data request apps available in the Nextcloud Compliance Kit. Using the applications in the kit as well as extensive documentation, supported by our compliance expertise accessible through their Nextcloud Subscription, Nextcloud customers can ensure full legal compliance with a minimum of effort. You can learn more on our website.
Closing
Besides all the big things mentioned above, lots of smaller improvements were made, like the use of the new ARGON2I hashing algorithm – if you don’t know what that means, don’t worry, that is a healthy thing! It simply means our team makes sure to take care of both the small and large things. If you have any feedback or want to contribute, you can contact us over github or get preferential access to our developers through a Nextcloud Subscription.
DIE ZEIT, a prominent German outlet, interviewed Nextcloud’s founder Frank Karlitschek for an article on Microsoft’s anti-competitive behaviour on the European office software market. Read for a recap of the article and the key takeaways.
MagentaCLOUD’s migration to Nextcloud in 2021 resulted in a fully equipped Online Storage with an integrated online office suite that further improves the user experience, flexibility and security for customers.
The Nextcloud Community Conference is not your average event - it's a community meetup that brings together Nextcloud enthusiasts, contributors, developers, users and industry experts from all over the world.
We bring you a major update to the Nextcloud AI Assistant, plus the news we work with several big hosting providers like IONOS and OVHcloud to bring AI-as-a-Service options to you!
Bechtle and Nextcloud announce today a complete managed collaboration platform for the public sector that requires no tender and can be deployed immediately.
Discover how to make the switch from ownCloud to Nextcloud. Our quick guide provides insights into the migration process, helping you make the transition smoothly.
Today, US-based file sync & share vendor Kiteworks announced their acquisition of ownCloud and Dracoon. Kiteworks points out that their customers now have access to their file-sharing application. It is to be expected they will not maintain 3 similar products, but customers will have to migrate to the US firms’ platform or look for another […]
As part of Schleswig-Holstein's state digitization strategy, the state chancellery has announced they will work with Nextcloud to develop AI for working with government documents. This comes just after we announced the first private AI assistant last weekend with Hub 6. The German state already uses Nextcloud and their AI strategy aligns with our work on ethical, local AI technologies.
Over the last year, AI has become a popular topic. Some is hype, some is substance. Some is good, some is bad. We want to give you the good, not the bad, and ignore the hype! AI has a ton of opportunity – but also risk. So we put you in control – off by […]
We save some cookies to count visitors and make the site easier to use. This doesn't leave our server and isn't to track you personally!
See our Privacy Policy for more information. Customize
Statistics cookies collect information anonymously and help us understand how our visitors use our website. We use cloud-hosted Matomo
Matomo
_pk_ses*: Counts the first visit of the user
_pk_id*: Helps not to double count the visits.
mtm_cookie_consent: Remembers that consent for storing and using cookies was given by the user.
_pk_ses*: 30 minutes
_pk_id*: 28 days
mtm_cookie_consent: 30 days