Attackers hit one server. Every member learns.

The EFA Collective is a signed, continuously updated blocklist of addresses caught attacking file servers — brute-forcing logins, guessing share links, probing WebDAV. Install the EFA Collective Shield app on your ownCloud or EFAdrive server, confirm your email, and your server starts screening logins against it within minutes.

Connect a server

We'll email you a confirmation link. Nothing is issued until you click it.

What your server gets

The collective blocklist, signed with ed25519 and verified on your server before use. Listed addresses are denied at the login, public-link and WebDAV surfaces — in log-only mode first, so you can see hits before you enforce.

What your server gives

With reporting on, failed-login and failed-share-password sources are sent back as sightings: source IP, kind, time and your host name. Sightings from new members are corroborated before anything is blocked anywhere.

What we store

Your email, the server host name, the app version and when it last pulled the feed. That's it. One click unsubscribes and revokes the server's keys.

Already running EFAdrive?

Open Settings → Security → EFA Collective Shield, enter your email, and the app does the rest: it registers the server here, you confirm the email, and the app picks up its keys automatically. The EFAdrive installer asks the same question during setup.