4 ms·
Paaster – Secure by default end to end encrypted pastebin
- dane-pgp 5y ago> Can I trust a instance of paaster not hosted by me? > No. Anyone could modify the functionality of paaster to expose your secret key to the server. We recommend using a instance you host or trust. That's refreshingly honest, but I hope that some day a technology like WhatsApp / Cloudflare's recently released "Code Verify" extension helps to solve this. https://inside.com/campaigns/inside-dev-2022-03-11-31674/sections/274213 https://inside.com/campaigns/inside-dev-2022-03-11-31674/sec...
- jimsi 5y agoI think that providing API to be used by standalone clients is far more better approach
- derefr 5y agoAFAICT you could permanently trust a webapp loaded from an IPFS-scheme URI (as e.g. Brave can do), after it’s been audited once.
- fastball 5y agoBut then if you're using an IPFS gateway instead of hosting your own instance then the gateway could serve you different content, no?
- fwtf 5y agoSince you request data by a hash, and your software should verify the downloaded data has the same hash, no.
- stavros 5y agoIf you're using a gateway, you have to trust the gateway.
- arlort 5y agoYou could probably have a pretty light wrapper around the gateway which verifies the hash. It wouldn't be as easy as simply using a gateway but still much easier than hosting/implementing an IPFS node locally
- stavros 5y agoWell, to use the node locally you just run a binary, it's not like there's much to it.
- indigodaddy 5y agoText input seems to be broken on mobile? (iOS Chrome)
- bts4 5y agoPinterest open sourced a similar tool a few years back - Snappass: https://github.com/pinterest/snappass https://github.com/pinterest/snappass
- amir734jj 5y agoI wish there was a way to create a link which doesn't contain the password so I can send the password separately.
- bennyp101 5y agoLooking at https://github.com/WardPearce/paaster/blob/Development/paaster-frontend/src/components/ViewPastes.svelte https://github.com/WardPearce/paaster/blob/Development/paast... the link is just concatenated with # - navigate(`/${pasteId}#${paste.clientSecret}`)} So you could just copy the link as everything before the # and send the rest as the password separately
- fastball 5y agoYep, that's exactly how it works. It's the same concept as how mega.nz do their E2EE.
- est 5y agoMight as well use WebRTC to establish realtime e2e p2p pasting.
- Biganon 5y agohttps://0bin.net/ https://0bin.net/ has existed for quite some time now