Discovery server security concerns

Hi everyone! I’ve using Syncthing for a while at home and now I wanted to use within my work team to, well, sync things, but IT team got concerned about it, specially about the discovery servers and they asked me a few questions to verify it’s usage:

  • Where is the global discovery server located?
  • Who operated that server?
  • What terms & conditions?

So far I’ve found this forum topic, but is from 2015 and I don’t know if it still applies. Is this information anywere I can see? Or does someone know how to properly answer those questions?

Thanks in advance for your replies and for your work in this great tool!

Víctor.

The closest thing to an answer is probably what is documented here. The services are operated by the Syncthing Foundation or, in practice, me. We have not written terms or conditions. I could tell you where they are, or you can probably easily figure it out, but it has changed historically and will likely do so again in the future so if this is an answer you depend on, the service may not be for you.

You could run your own Discovery Server infrastructure.

And in addition to @chaos : Or disable the usage of the discovery server, if you have fixed IPs.

For sure. Or use FQDNs (which is what I do).

Thanks everyone, since we are in Europe I guess the question about the location of the servers is because the custody chain of the data and if they’re protected by GDPR or something like that. I’ll try to push to create a private discovery server within the company, since it seems the most secure solution.