4 ms·
If anyone is interested, after firefox send shutdown, i wrote https://www.relaysecret.com https://www.relaysecret.com, its footprint is extremely small (1 lambd
by ebfe1 4y ago
If anyone is interested, after firefox send shutdown, i wrote https://www.relaysecret.com https://www.relaysecret.com, its footprint is extremely small (1 lambda function that does all signing for s3 upload/download, simple frontend code that does encryption in browser using web crypto api with no 3rd party Js, no 3rd party css, no tracking. Anchor tag is used for additional random key material (so it wont leave ya browser and files will always be encrypted regardless).
You can roll your own too with the terraform code in it. It costs me barely anything (never go over free tier limit) to run it because files never live more than 10 days (there is a catchall lifecycle rule on the bucket) and when users select durations, i also put them in bucket prefix that has lifecycle rule place on objects under them for that duration. Note that we can't rely on lifecycle rule all the time so i also make sure when lambda is called to access the object, it checks the time-stamp, the duration and if it is meant to expire and not yet cleaned up by s3 - lambda function deletes it.
I learnt a ton of cool things about s3 after this neat little project and really dig the API, the lifecycle rule, signing url etc...
Ps: for these type of tool, you should definitely mitm it to see if plaintext file or password ever leave the browser... Relaysecret does leave one item unencrypted and that is the file name. You can change it upon upload but i like to leave it there so people know what they are downloading. I have simple idea of encrypting that with just the anchor key but haven't gotten around to put that in yet.
- laurent123456 4y agoVery interesting, but why is the password optional? Doesn't it mean that someone with access to the S3 bucket can decrypt the data?
- rahimnathwani 4y agoThe file is encrypted before upload. The decryption key is supplied in an anchor tag. This is the case even if there's no password.
- ebfe1 4y ago100% this but note that the user entered password is not included in the anchor tag so if you add a password, recipient still needs to enter the password to be able to decrypy and download ;)
- ebfe1 4y agoAha that is a great question! There are 2 parts of the key, one is the anchor tag key (the part behind # that you see in download url) and your password. The anchor tag key part is ALWAYS generated randomly in the browser so that your file will be encrypted no matter what even if you forget to enter password and hit upload. Note that the anchor tag part does not leave the browser so it is one of the clever thing firefox send used to share some id/key. You can double check it in the network tab ;) If you are worry about that key being leaked somehow, adding a password ontop is a good measure.
- laurent123456 4y agoThat makes sense, thanks for clarifying!
- Hnaomyiph 4y agoThank you for this. I just bookmarked it. When Send shut down I've constantly been searching for a better transfer program that doesn't require any client-side setup besides a link. I've been using https://sendight.ml/ https://sendight.ml/ recently, but occasionally get corrupted files for reasons unbeknownst to me, but beyond that it's the best one I've found so far, no connection to them, just found it on a reddit thread.
- ebfe1 4y agoOh wow! I didn't know this reply got so much like, thank you! Sendlight.ml looks awesome and on that note, to make things easy to share between devices, i made a simple "tunnel" mode as well, you can try it here: https://www.relaysecret.com/tunnel https://www.relaysecret.com/tunnel The way it works is super simple: the anchortag is base on the tunnel name (first round of sha256 if my memory serves me well) and the actual "tunnel id" is a few first characters of the second round of sha256. This way by enter the same "tunnel" both devices can share file without the need to share long complicated urls. The files in tunnel only lives up to a day. Unlike sendlight though, it is not peer2peer webrtc and it is using the same lambda backend to create signed urls for s3 and encryption done in browser like before, just a neat little trick to have a simple way to setup "room" between devices ;)
- timvisee 4y agoI'm have been hosting Send for a long while at send.vis.ee. You might find it useful!
- substation13 4y agoFYI the LinkedIn URL on your website is broken
- m348e912 4y agocool web app, commenting to save for later
- 411111111111111 4y agoIf you click on the timestamp of a comment there is an additional option to favourite a comment. These are then visible from your profile until you remove this toggle
- m348e912 4y agothx!