4 ms·
0bin: A Client-Side Encrypted Pastebin
- tomlanyon 14y ago"Error Paste could not be saved. Please try again later." Damn.
- sametmax 14y agoJust fixed that. First day out, first bug out :-)
- rabidsnail 14y agoThe problem with these is that even if the code is set to be cached forever, there's no easy way for the user to verify that this is the case. How do you defend against an attacker (say, the FBI) taking control of the servers and causing them to serve javascript which sends the messages to themselves unencrypted?
- arkem 14y agoAt the moment an attacker doesn't even need to take control of the servers since all the code is sent without SSL so a MITM attack would be enough. Edit: though of course if the javascript is never requested again it limits the window of opportunity to man-in-the-middle.
- jmah 14y agoThough of course if the HTML is requested again you could just add another script tag.
- sturmeh 14y agoThis was on HN previously, but not at this domain, they said the key generation and link formation was performed client-side, at no point does the key get sent to the server. You send the encrypted message to the server and the javascript serves the url that combines the client side key and the servers uid for the paste. See: http://sebsauvage.net/paste/ http://sebsauvage.net/paste/
- fatjokes 14y agoThis should be a top-level comment.
- sametmax 14y agoYou don't. That's not the purpose. 0bin is not made to prevent the user from being buster. 0bin is made so that it's difficult to sue the host for hosting hot content since he can claim he can't moderate it.
- mxxx 14y agonice idea though.
- Aeons 14y agoJust a note, the 0 (zero) in the page logo/title is (or looks a lot like) the Scandinavian letter Ø, which is in no way related to the number 0.
- cnu 14y agoThe short URL feature doesn't work. The short URL created is http://0bin.net/paste/undefined http://0bin.net/paste/undefined