Priviy
chiffrement-cloudINFO

Syncthing Is Not a Backup, and Its Own FAQ Says So

Syncthing keeps your devices identical without a cloud provider in the middle. Its documentation is explicit that this makes it a poor backup, and equally explicit about what a device ID reveals. Both matter before you rely on it.

By Eric Gerard · Editor · Priviy4 min readPhoto via Pexels

Syncthing solves a problem most privacy tooling does not even attempt: keeping several devices in step without a company in the middle holding the files. What it does not solve is the one people assume it does, and the project says so itself.

The sentence that should come before any setup guide

From the official FAQ:

Syncthing is not a great backup application because all changes to your files (modifications, deletions, etc.) will be propagated to all your devices.

Read the parenthesis. Deletions are changes. A file removed on your laptop is removed everywhere, because that is precisely what synchronisation means and precisely what you asked for.

This is the same trap that catches people with any synced folder, and it is worth stating in the same breath as the feature: a mirror shows what is in front of it, including an empty room. If you delete something by accident, or a piece of software deletes it for you, Syncthing does its job faithfully and the mistake reaches every device you own.

Versioning exists in Syncthing and mitigates this, but it is a setting you choose, not a property you inherit.

Where your data actually goes

Two modes, and it is worth knowing which one you are in.

Direct connections are the preferred path: the devices talk to each other.

Relays are the fallback when a direct connection cannot be established, typically because both ends sit behind restrictive networks. On this point the FAQ is categorical: relays do not and can not see the data transmitted via them.

The documentation also tells you how to check rather than assume, by looking at the Connection Type in the Remote Devices list. That is a small habit worth having, because a relayed connection is slower and tells you something about your network that you probably want to know.

A man holding a mirror that reflects a second person standing outside the frame.
A man holding a mirror that reflects a second person standing outside the frame.

What a device ID gives away

This is the part that deserves a clear answer rather than reassurance in either direction.

The FAQ states that given a device ID it's possible to find the IP address for that device, if global discovery is enabled on it. So an ID is not a public identifier you should scatter around: it is linkable to where you are.

And then the limit, stated just as plainly: knowing the device ID doesn't help you actually establish a connection to that device or get a list of files.

Both halves matter. A leaked ID is a privacy consideration, because it exposes an address. It is not a security breach, because it grants no access. Treat it roughly as you would treat your home IP: not secret exactly, not something to publish either.

Device IDs also cannot be forged, and that is enforced cryptographically. It is the reason pairing requires both sides to accept, and the reason the ID is long enough to be annoying.

Two things it is not designed for

It is not designed to sync locally. Two folders on the same machine is not the job, and the documentation says so. Reach for a file-level tool instead.

It is not a backup, which is where we started, and the fix is not to argue with the tool. Pair it with something that keeps history: versioning inside Syncthing, or a genuine backup that retains what you deleted.

The honest summary

Syncthing keeps devices identical without a provider in the middle, and it is unusually candid about the consequences. Deletions propagate, because that is what synchronising means. Relays cannot read your traffic. A device ID can reveal an IP address if global discovery is on, and nothing more than that.

Use it for what it does, add versioning or a real backup for what it deliberately does not, and check the Connection Type once rather than assuming you are connected directly.

The statement that Syncthing is not a great backup application and its reasoning about propagated changes, the relay behaviour and the assertion that relays cannot see transmitted data, the device ID and global discovery wording including its stated limits, the impossibility of forging device IDs, and the note that Syncthing is not designed to sync locally, are taken from the official Syncthing FAQ, checked at the time of writing. Behaviour can change between releases; verify against the version you run. Commercial links carry the rel="sponsored nofollow" attribute; an affiliate commission may apply at no extra cost to you.

Frequently asked questions

Can I use Syncthing as my backup?
Its own FAQ answers this directly: Syncthing is not a great backup application because all changes to your files, modifications and deletions included, will be propagated to all your devices. A deletion is a change like any other, so it travels to every device you sync. That is the correct behaviour for synchronisation and the wrong behaviour for a backup.
Do my files pass through Syncthing's servers?
Not in the sense people fear. Devices prefer direct connections, and fall back to relays only when a direct connection cannot be established. On relays, the documentation is unambiguous: relays do not and can not see the data transmitted via them. You can check which mode you are in through the Connection Type shown in the Remote Devices list.
What does my device ID reveal?
One thing, and it is worth knowing. The FAQ states that given a device ID it is possible to find the IP address for that device, if global discovery is enabled on it. It also sets the limit: knowing the device ID doesn't help you actually establish a connection to that device or get a list of files. So a leaked ID exposes an address, not your data.
Can someone impersonate one of my devices?
No. Device IDs cannot be forged, which is prevented cryptographically rather than by policy. That is why adding a device is a mutual operation and why the ID is long enough to be inconvenient to type.
Can I use it to sync two folders on the same machine?
The documentation says it is not designed for that. Syncthing is not designed to sync locally, and using it that way fights the tool rather than using it. For same-machine work a file-level tool is the right answer.
Choix éditorial
4.5 / 5

Add zero-knowledge encryption → pCloud Crypto

Client-side encryption · only you hold the key · Swiss jurisdiction

Société suisse depuis 2013Satisfait ou remboursé 10jFree 10 GB
Voir l'offre