The six jobs of file sync
Sharing a folder between two machines takes six jobs. A cloud drive does all six on its own servers. Every alternative moves some of them off those servers, and leaves the rest there or goes without them.
| Job | The question it answers |
|---|---|
| Identity | Who is this person, across the machines they run? |
| Permissions | What may they read and change? |
| Storage | Where do the bytes sit while every machine is off? |
| Transport | How do bytes get from one machine to another? |
| Discovery | Where is that machine on the network right now? |
| Convergence | When two machines write at once, what is the result? |
Permissions on one machine
Unix permissions name a user by a number that is local to one computer. NFS shared a disk over a network in 1984 by trusting the user number each client sent, which the protocol's RFC calls insecure. It works where one administrator owns every machine.
One server, all six jobs
Dropbox launched in 2008. An account on Dropbox's servers is the identity, and the same servers do the other five jobs. One company holds the files and decides who can open them.
Systems that moved some jobs off the server
BitTorrent moved transport and storage to peers in 2001, for public files only. Bytes are verified by hash, so they can come from anyone, and anyone can read them.
Git moved convergence to the client in 2005, for text that a person merges by hand. Permissions, transport and discovery went to a hosting service.
In 2007 Tahoe-LAFS moved storage to hosts that hold only ciphertext. Whoever holds a file's capability string can read or write it. Tahoe-LAFS supports one writer at a time, has no notion of who anyone is and does not pay its hosts.
In 2013 Syncthing moved identity and transport onto the devices themselves, and it does both well for one person's own machines. A folder is shared with a device or it is not, with no roles inside it, and a change waits on the device that made it while the other device is off.
Keybase moved identity and permissions onto keys in 2014, with real roles and end-to-end encryption. Its servers still store the files, relay them, hold half of each team key and sign the record of which keys belong to whom.
Peergos has per-directory read and write capabilities that can be revoked, on servers that see only ciphertext. Identity is a username registered with one global server.
Who does each job
| System | Identity | Permissions | Storage | Transport | Discovery | Convergence |
|---|---|---|---|---|---|---|
| Dropbox | server | server | server | server | server | server |
| BitTorrent | none | none | peers | peers | tracker, DHT | none |
| Git | unverified | server | every clone | server | server | manual merge |
| Tahoe-LAFS | none | capability | blind hosts | direct | server | one writer |
| Syncthing | keys | whole folder | devices only | direct | blind servers | conflict copies |
| Keybase | keys, server root | roles, server gate | server | server | server | server |
| Peergos | server | capabilities | blind hosts | via hosts | server | not documented |
| Rift | keys, one person many machines | signed roles | Sia, blind, paid | direct, or a relay | blind servers | automatic, conflicts kept |
Blind means it cannot read the files.
Recent building blocks
Sia pays its hosts to keep encrypted data, which Tahoe-LAFS does not.
Until recently, merging edits automatically needed a server, and so did settling two admins' changes to who has access. Automerge merges concurrent edits to structured data with no server choosing a winner. Keyhive, from the same lab as Automerge, does the same for permission changes. Two admins can grant and remove access while offline and every machine reaches the same member list.
iroh connects two machines by public key through NATs, and its relays cannot read the traffic.
What Rift adds
Rift did not invent these parts. It puts them in one filesystem. That gives it roles, automatic merging and storage that stays available while every machine is off, and none of the three needs a server that holds a key or decides who has access. None of the other seven systems in the table documents all three without such a server.
What is still open
Discovery still depends on servers. Rift finds machines through DNS records and relay servers. The relays cannot read traffic, but an operator has to run them.
Removing a key's access cannot delete files a machine already downloaded. In every system on this page, a machine that has a file can keep a copy of it.
Written from the documentation of Tahoe-LAFS, Syncthing, Keybase, Peergos, Sia, Automerge and iroh. Also from the Git book, the Keyhive notebook and the RPC specification NFS uses. Dates for Dropbox and BitTorrent are from Wikipedia. All read in October 2026.