5 ms·
Show HN: Temp.pw
- yawndex 1y agoWhy does the "share" button upload the password to your server in plaintext?
- zamadatix 1y agoThe "share which expires after one use" part requires the password either be visible to the server or encoded in the URL (also visible to to the server) unless you also want to share a password/key to access the password or, in which case the site doesn't make sense, or you want to require both folks are online at the same time to make a brokered WebRTC connection and share via that channel. I think the intent is you have some crap messaging platform like email or SMS without and want to send a one time access link to the password. I'm not really sure how large the intersection of people who care enough about security to want that but not enough to want to avoid a 3rd party server and hoping first access of the link contents is by the intended target is though.
- new_user_final 1y agohttps://temp.pw/?item=82282c4798d60cb4#key=idh36ud https://temp.pw/?item=82282c4798d60cb4#key=idh36ud I think something like this could work. The server store encrypted password identified by item id. Browser side decrypt the encrypted password using key in the hash part. The hash part does not reach the server.
- zamadatix 1y agoThe full URL gets sent to the server on connection. You could break this out from the link, at which point you're back to sharing a password to share a password.
- Edd314159 1y agoIt has to, how would it deliver the password to the URL’s recipient otherwise? I suppose to keep it fully stateless you could encode the password in the URL itself somehow, but then that would defeat the purpose of not having the secret hang around in perpetuity.
- bn-usd-mistake 1y agoEncrypt password with a given key, send that to the server. Include the key in the `#fragment` of the URL to Share.
- Edd314159 1y agoOh I was just talking about the “transmitting to the server _at all_” part, but yeah some end-to-end encryption would be nice.
- new_user_final 1y agoFeedback: Input box gives zero clue that it is editable. Share button looks disabled button.
- Minor49er 1y agoThis generates a random password that can be shared via a one-time link. Why? What is the situation where this would be used?
- ca98am79 1y agowhen you want to share a password with someone but don't want the password to remain in chat history
- eigenvalue 1y agoHoneypot?
- ca98am79 1y agoHow would I connect it with any username or login? I just made it because I wanted something like this and make it available to others in case they find it useful. It is free and no ads
- TimTheTinker 1y agoIf you were a cracker, you'd add every one of these passwords to a database (maybe of up to 10B passwords) to try first before moving to cracking hashes.
- 0xFACEFEED 1y agoHoneypot.
- a3w 1y agoWhy is the Share button greyed out, but clickable? Did you vibe code this? (Those are two distinct questions, but yes, I was low-balling the effort that went into this web app.)
- ca98am79 1y agoI don't know why the share button became that color. I actually made this years ago because I needed it for my company. But then file.io was acquired (which I was using for the backend), and so I had to recently switch to using aws as the backend. So I vibe-coded a new backend api for aws in the last couple of months. I also acquired the domain temp.pw - previously used temporary.pw (which still works).
- deleted 1y ago[deleted]
- ziddoap 1y agoThis is pretty light on features and details. When the use case comes up, I like to use https://github.com/pglombardo/PasswordPusher https://github.com/pglombardo/PasswordPusher (online version here https://pwpush.com/ https://pwpush.com/). Which has generation, customizable # of visits, and a handful of other features.
- ca98am79 1y agoyes I made it super simple on purpose, but pwpush looks cool!
- thom 1y agoNice try, Satan.
- esafak 1y agoI just use my password manager. https://support.1password.com/share-items/ https://support.1password.com/share-items/
- qntmfred 1y agonice work. i've used https://onetimesecret.com/ https://onetimesecret.com/ for this kind of thing for several years
- matrixhelix 1y agoopenssl rand -base64 12
- motohagiography 1y agosolves a common problem. assuming there's a real crng generating them, the links expire in a short window, they aren't logged, and the hashes aren't computed for a commercial rainbow table, what are the specific security objections to this? its like a vault secret without the authn friction.
- dgrin91 1y agoA fun side project I guess, but I would never trust this for anything. Why would I use this instead of an actual password manager that has password sharing functionality? That also would not save a pw in chat history and has the added benefits on real security and not being some random site.
- ca98am79 1y agobecause it is about sharing a one-off password with someone so that you don't have to worry about it getting stored in chat history
- TimTheTinker 1y agoThis is so, utterly, unspeakably, NOT a good idea to use. You're trusting a third-party server with the plaintext of an actual secret. This violates nearly every principle of good modern security. If the author had somehow built and documented (and proved) a true zero-trust model that enables this kind of interaction, then that might be cool. But that is not this. For all we know, the author (or an insider threat working at AWS) is collecting these passwords into a database for crackers to try first before proceeding to cracking password hashes. There are so many other ways to do this. E2E encrypted messaging with disappearing messages (Signal) is the bare minimum. Keybase messages (also E2EE) are also a semi-decent option. 1Password password sharing is a decent usability step up from those. For all three of these options, barring a compromise of the (carefully guarded) process for shipping frontend code to users, the security design guarantees no visibility to a third party, and they have white papers that go into great depth to explain why.
- ca98am79 1y agoyes truly awful, I should be ashamed for making it. Why do I make anything. Thank you for the feedback
- TimTheTinker 1y agoSorry, nothing personal. :) No shaming/accusation intended - all I intended was a warning to potentially naive readers about the security principles involved. Keep building, the UX is great. Unfortunately, security stuff has some pretty hard lines we had to start drawing and moving further forward due to excellent security research (of whatever color hat)...
- ca98am79 1y agothanks. I think security is super important, however I do not think it is necessary to obsess over it for no reason. If I want to share a dev password with someone, I can tell them the login over discord and then send them a link to temp.pw. Easy peasy and absolutely no security risk. This is why I created it.