# Security of private ipfs network

**URL:** <https://discuss.ipfs.tech/t/security-of-private-ipfs-network/1324>\
**Category:** Help\
**Created:** [October 25, 2017, 7:25pm UTC](https://discuss.ipfs.tech/t/security-of-private-ipfs-network/1324 "2017-10-25T19:25:51Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![rklaehn](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ipfs.tech/rklaehn/32/244_2.png) [@rklaehn](https://discuss.ipfs.tech/u/rklaehn)\
**Post date:** [October 25, 2017, 7:25pm UTC](https://discuss.ipfs.tech/t/security-of-private-ipfs-network/1324/1 "2017-10-25T19:25:51Z")

</div>

When running a private ipfs node with a private swarm key in the cloud, is it reasonably safe to leave port 4001 open to the internet?

We want to use ipfs to redistribute assets within our company.

We have already created a private ipfs network spanning a local machine and some android devices (i386 as well as arm). Other than some android issues, it was very straightforward.

It would be very convenient to have a cloud-based node that is reachable over the internet. However, I am a bit unsure about the security implications.

Can somebody point me to some documentation describing how the swarm key is used? If it is very insecure, we could always do this via an ssh tunnel. But I would like to avoid that.

---

<div class="post-metadata">

**Author:** ![lgierth](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ipfs.tech/lgierth/32/11_2.png) [@lgierth](https://discuss.ipfs.tech/u/lgierth)\
**Post date:** [October 26, 2017, 3:20am UTC](https://discuss.ipfs.tech/t/security-of-private-ipfs-network/1324/2 "2017-10-26T03:20:09Z")

</div>

Sounds cool! It’s fine to leave this port open. You can read a spec in [https://github.com/libp2p/specs/pull/10](https://github.com/libp2p/specs/pull/10) - it’s needs a few cosmetic changes, but is otherwise accurate and reflects what go-ipfs currently does.

---

<div class="post-metadata">

**Author:** ![rklaehn](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ipfs.tech/rklaehn/32/244_2.png) [@rklaehn](https://discuss.ipfs.tech/u/rklaehn)\
**Post date:** [October 26, 2017, 12:13pm UTC](https://discuss.ipfs.tech/t/security-of-private-ipfs-network/1324/3 "2017-10-26T12:13:06Z")

</div>

Thanks a lot for the quick answer.

So it is using the well-known cipher [Salsa20](https://en.wikipedia.org/wiki/Salsa20) in a pretty straightforward way. My conclusion is that we can leave the port open as long as we have a secure way to distribute the shared secret (we have that).
