12 ms·
Show HN: Share It, Anonymously with Self Destruct Messages
- shazron 5y agoCheckout Zerobin (now privatebin). No database required, has expiry. All decryption/encryption in the browser. zerobin: https://sebsauvage.net/wiki/doku.php?id=php:zerobin https://sebsauvage.net/wiki/doku.php?id=php:zerobin privatebin: https://privatebin.info https://privatebin.info
- jassra 5y agoHi, normally i dont post at all. But this is my attempt to share pieces of information anonymously that expires in a certain time. Site is made in Angular and and the backend is a simple thread safe dictionary that resets every 24 hours. It is by no means a commercial solution to any problem. This is something i came up with half an hour of dev work, coz i could not find anything similar.
- mds101 5y agoIt looks very good for something whipped up in an hour. Did you consider using Redis as a data store for this? Seems like it would be quite easy to just generate a UUID as a key and set it with an expire time in redis. If you did consider Redis, any reason why you didn't end up using it?
- KMag 5y agoIf you want privacy and anonymity, be careful about how you're generating your UUID. Some flavors of UUID are just the MAC address, process ID, and timestamp, which makes them trivially guessable (and poorly scalable). Instead of a UUID, just read 16 bytes from /dev/urandom (getentropy() if you've got it). Base85 or Base64 encode the bytes if you need a string.
- NicoJuicy 5y agoAny resource about this? Someone mentioned it before and it seems false. UUIDS are made to scale and i think it's mostly about a lack of understanding of UUIDS. Eg. some versions of UUIDS are meant to be deterministic, some for sortability, ... https://en.m.wikipedia.org/wiki/Universally_unique_identifier https://en.m.wikipedia.org/wiki/Universally_unique_identifie...
- KMag 5y agoIt was over 20 years ago now, and I don't remember which library it was, but I ran across a type-1 UUID library that stored the timestamp of the latest UUID it handed out in a static (or maybe thread-local, I forget) variable, and would nanosleep until the system clock next ticked if it had already handed out a UUID with the current timestamp. So, you were limited in your UUID generation rate by the resolution of the system clock. (I guess the fear was that it was theoretically possible for the process to crash and come back up with the same PID/TID within the same system clock tick, if the machine were really chewing through processes rapidly. It's good, as they aren't called Nearly Unique IDs, and the main use for type-1 UUIDs would be if you're paranoid about RNG collisions, but it does limit you to one ID per system clock tick, even though the timestamp in the type-1 UUID is actually 100-nanos resolution.) A better solution would have been to query the system clock resolution, at library initialization time check the current system timestamp, and use the low bits of the type-1 UUID timestamp as a counter, being careful to never catch up to the current time. The library wouldn't have been able to hand out any UUIDs during the first system clock tick after library initialization, but after that, it could hand out up to 10 million UUIDs per second per thread. If that's not fast enough, one could also have it check for multiple network cards and use a pool of MAC addresses instead of just the primary interface's MAC address.
- NicoJuicy 5y agoIt was only proposed as a standard in 2005. So perhaps the first versions of it were not efficient? I definitely didn't had issues the last 10 years ( .net )
- 5y ago
- jassra 5y agoLove the idea. I ll implement : ) Thanks for visioning better !
- loa_in_ 5y agoRedis looks like the perfect tool, with reliable inbuilt expire mechanic.
- shoto_io 5y agoNice. Is there any way one could proof that data is really deleted? Not questioning your honesty, just curious.
- huhtenberg 5y agoThat's obviously impossible.
- shoto_io 5y agoIs it? There has got to be a blockchain magic way
- agildehaus 5y agoBlockchain or not, copying to something non-blockchain is always a thing.
- robobro 5y agoHow could blockchain prove that something was deleted?
- wftglf 5y agoNice work! In the past I've used https://privnote.com/ https://privnote.com/ for this kinda thing but it doesn't allow as short self destruct times
- traspler 5y agoJust fyi, going to „https://pastenow.me“ https://pastenow.xn--me-x2t without the „www“ just gets me to a „Hi“ page without any content.
- jassra 5y agoSorry. as i said, i just did it in little time with only www mappings.
- asicsp 5y agoSince this is your own project, 'Show HN' [0] would be more appropriate. [0] https://news.ycombinator.com/showhn.html https://news.ycombinator.com/showhn.html
- jassra 5y agoAgreed, how do i edit this
- huhtenberg 5y agoPage never finishes loading vendor.js. The rest of .js seems to be loading OK. Edit - Nevermind, it finished loading. Took 1.24 min in total.
- jcla1 5y agoI never really got the point of (digital) self destructing messages, since the reader can easily just copy the text/data, i.e. destruct only means not available anymore after future point in time. So you're just relying on the receiver of the message to follow protocol -- as always.
- afroboy 5y agoI use it a lot with my friends (Signal) when speaking in very sensitive subjects instead of deleting messages manually you just make sure that messages will not be available after a specific time so you are safe if someone hacked your phone. and yes it's very useful if both parties agreed to it. is not security against the one who are chatting with but the one who might access your data one day.
- blowski 5y agoI hadn’t thought of it that way. I guess it’s like shredding mail is completely normal, but in a digital world we’ve become accustomed to the idea that you keep every single letter forever.
- exo762 5y agoIt protects you from negligence, not malice of your conversation partner. There is an obvious design trade-off since people might use this feature in a wrong setting.
- jassra 5y agoNot exactly the case always, in this case atleast there is an effort from the source side to remove it from its end.
- pydry 5y agoCurrent reader and future reader are different people. Spouses get divorced, business partners fall out, friends lose touch, etc. There is also value in a message that the reader would have to knowingly and immediately violate the writer's trust in order to keep.
- 5y ago
- nathias 5y ago400 error for me when I press Go, request payload: Invalid Origin (on arch/firefox nightly)
- sidcool 5y agoI am repeatedly getting 'Request Failed' while trying to create a paste.
- soulmerge 5y agoI usually use https://onetimesecret.com/ https://onetimesecret.com/ for sharing secrets. Its code is also on github, so you can install it in your own environment, too, if you don't trust the author. https://github.com/onetimesecret/onetimesecret https://github.com/onetimesecret/onetimesecret
- telesilla 5y agoI use https://www.saltify.io https://www.saltify.io however I didn't know onetimesecret is open source, this is helpful as we use it a lot at work, seems worth building our own. Thanks for sharing that.
- deleted 5y ago[deleted]
- hardwaresofton 5y agoTaking advantage of this post to ask about this -- can anyone explain to me why Signal can't be implemented as a completely offline-first/PWA web-app. If we throw away the more advanced requirements of perfect forward secrecy, non repudiation, ratcheting for groups, non repudiation, why is it a bad idea to get 80% of the way there with basic offline-first/WPA (+/- secure enclave, WebAuthN, whatever else) messages that are stored on peoples' devices, encrypted before being sent out etc. Excalidraw is an excellent app that's actually already written about this[0], so we know it's possible in some form. There's exciting p2p technology in the browser (ipfs, gun, etc). To reach all the platforms you could use Electron and in the future Tauri (which purports to be less of a drain on system resources), etc. What am I not seeing about why this fundamentally can't be done and I can enjoy relatively simple encrypted chat without worrying about installing too many things, in a throw-away shell somewhat similar to pastenow.me? Is it just that no one has built it? surely not NOTE -- I don't mind too much about not having to be online at the same time to share information with someone else, I don't think it's too hard these days to coordinate a time to share initial contact information/status [EDIT] correct "offline" to "offline-first/PWA" since it was leading to confusion, didn't include the "-first" enough places, clearly.
- finance_br0 5y agoI don't get it. Why would a messaging app be offline? Do you mean you could send out messages even while you're offline, and the app would wait until it has a connection and send those messages out immediately?
- deleted 5y ago[deleted]
- hardwaresofton 5y agoSorry the offline there is "offline-first", you need offline-first (AKA modern PWA type technology/architecture) for websites to work well in patchy internet/etc. The "offline-first" phrase/terminology is well known in frontend circles but maybe not as widely as I thought. Generally offline-first/PWAs can be made "installable" by setting metadata on the page that hosts them and doing other things.
- jassra 5y agoJust fixed it
- avh02 5y agofor the longest time we had issues with people pasting passwords in slack to share them within the org. one hackathon later we had a one time secret sharing slash command (which you can only reveal the message once and is then lost/deleted). self-hosted. it's the thing i'm asked most about if it was OSS after i left the company (by other ex-colleagues looking to have the same thing elsewhere).
- Dwolb 5y agoThat’s a great product by the way. Feels like a Freemium model based on number of unique users could be pretty effective.
- avh02 5y agoyeah, was thinking about rebuilding it as OSS just now. the biggest problem is that a security-minded org is going to want control over the server storing their secret messages (otherwise, you're literally giving away which org you are (slackbots get your org id) and your deepest secrets to a third party) to self-host, i think the slash command setup is more complicated/annoying. but i will look in to it again. edit: and you can't really do E2E encryption with slack as a middleman to your API
- jassra 5y agoIts the haunt of existing premiums that drove me to make this. :) Literally free : )
- jassra 5y agoI ll be honest here: I litreally did this because i was getting tired of not being able to find a platform where i can be confident that: Yes, from an end to end there is no middleman snooping etc. I ll publish the code on github too. The idea is that on every startup, system generates a new keys to encrypt data. This site is hosted on a single docker instance and there is no output (logs etc) for now. I dont intend to capture anything at all from this. Litreally. The dictionary lives in memory and there is a background service on the same docker that new(s) the Dictionary every 24 hours.
- premek 5y agowell now you have your platform where you can be confident that no one is snooping but if anyone else would like to use one too, they would have to make it themselves (or deploy your source code when you publish them)
- Tepix 5y agoWhat's wrong with the cryptpads? Anyway, a bit of feedback: 1. You really need a privacy policy 2. Instead of very long hexadecimal UUIDs use shorter IDs with more valid characters. Do you really need 128 bits for something that has to be brute forced and only lives for a limited time? Perhaps 64 bits are sufficient?
- loa_in_ 5y ago2) what would shorter IDs accomplish?
- quickthrower2 5y agoTyping URL onto mobile?
- vort3 5y agoCan't you just scan the QR code?
- zed88 5y agoJust curious how would something like this would handle the recipient taking a screenshot?
- known 5y agohttps://vim.cx/ https://vim.cx/ is what I've been using;
- Misiek_k 5y agoSame systems were introduced in 2003 when the sms messages were extremely expensive. Seems like the tech is going circles
- tiborsaas 5y agoLove these utility service. A couple of things I noticed: - It's not immediately clear that the message will self destruct from creation or starting from recipient opening it. - I created a test note and it says: "Expiring in a few seconds" but not even a minute has passed. - It would be nice to have some reference in the footer with some terms and who made this site.
- jassra 5y agoDuly noted. will update with tons of feature (that community suggested) this weekend :)
- bauripalash 5y agoIt would be something interesting, if it had name such as paste me with domain paste.me Still pretty good ,