Should I use Syncthing?
Open-source continuous file synchronization between your own devices - syncthing.net
Worth it. Buy if you're technical and want free, private device-to-device sync with no cloud middleman. Skip it if you want Dropbox-level simplicity, an iPhone in the mix, or someone to call when things break.
Confidence
Medium. Based on 40+ public sources; many snippets truncated, so depth is limited.
Ratings
- Value for money
- Ease of use
- Feature depth
- Support qualityCommunity forum only; no quality evidence
- Security posture
Pricing
$0
Desktop / server
ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Android (Google Play)Paid one-time
Managed hosting (Elestio)Varies
Best for
- →Self-hosters
- →Privacy-conscious multi-device users
- →Obsidian and note-sync users
- →Technical hobbyists
Not for
- ×Non-technical users wanting Dropbox simplicity
- ×iPhone-centric households and teams
- ×Businesses needing vendor support or SLAs
- ×IT managers wanting central admin of many users
Gotchas - check before you buy
high
iOS unsupported; syncing with an iPhone requires third-party workarounds
medium
Community forum is your only support; response times are unguaranteed
medium
Android is fragmented: official Play app costs money; free community forks exist
medium
Users report sync stalls; troubleshooting stuck folders eats time
Pros and cons
Pros
- +Completely free and open source; no subscriptions
- +Peer-to-peer: files sync device-to-device without any cloud server
- +Ranked as still the best peer-to-peer file sync tool
- +Users report it working impressively within minutes
- +Runs everywhere; managed hosting exists if self-hosting feels heavy
Cons
- −No native iOS app
- −First-time users flag setup and usability friction
- −Some long-time note-sync users gave up on it
- −Donation-funded: no vendor, no SLA, no support guarantees
- −Actively abused by hackers to exfiltrate stolen data
Sources & method
Analyzed 9/21/2026 - 12 sources - 3 CVEs disclosed (most recent patched June 2023); no breach of the project itself, but malware operators abuse the tool for data exfiltration.
official x3review x7security x1news x1
- CVE-2022-46165 — XSS in Web GUI, Medium-severity cross-site scripting in the web GUI, patched June 2023.
- CVE-2017-1000420 — symlink file write, Older symlink vulnerability allowing file writes outside synced folders.
- CVE-2021-21404, Low-severity vulnerability in syncthing; detail limited in sources.
- Abused by threat actors, Ukraine warned hackers use Syncthing to move stolen data — abuse vector, not a product flaw.
Comments
One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.
No comments yet.