4 ms·
So the decryption key contained in the url after the “#”? Is it never sent to the server, and instead only used to decrypt the message in-browser?
by surround 6y ago
So the decryption key contained in the url after the “#”? Is it never sent to the server, and instead only used to decrypt the message in-browser?
- selykg 6y agoRight, anything after the # is not sent to the server, like other anchors.
- tim333 6y agoI wonder how they know which message. I guess javascript on the client reads the stuff after # and sends something derived from it to the server?
- selykg 6y agoSo I created a test Send: https://send.bitwarden.com/#j_2g_Uin5kuwZazpASDD2w/vhzdAzIS3d30hmm2Ws3plg https://send.bitwarden.com/#j_2g_Uin5kuwZazpASDD2w/vhzdAzIS3... https://send.bitwarden.com/#VGacXlwPhUSVHKzpASEAyg/VrzFu9aUfcAjSXvy6MCccw https://send.bitwarden.com/#VGacXlwPhUSVHKzpASEAyg/VrzFu9aUf... So, it looks like it's pretty simple. After the # you have two separate things, separated by / One is an identifier, the other is likely an encoded key (that may or may not depend on a separate password, if specified). Just a guess, I assume this is documented somewhere