neverstored: hand over a secret without leaving traces

Andrea Fontana nospam at example.org
Wed Sep 16 10:42:50 UTC 2026


On Wednesday, 16 September 2026 at 08:20:25 UTC, Dejan Lekic 
wrote:
> On Monday, 14 September 2026 at 15:07:37 UTC, Andrea Fontana 
> wrote:
>
>>
>> Let me know what you think!
>
> Nice! Perhaps good for a company, though most companies 
> nowadays use stuff like LastPass which has this functionality 
> out of box. I like the idea and simplicity!
>
> Personally I just use OpenSSL or GPG (for bigger files), 
> encrypt file with my colleague's public key, and send encrypted 
> file to her/him via email. :) This is rare anyway (happens once 
> or twice a year), so OpenSSL works for me.

GPG/OpenSSL are definitely great for those who are already 
comfortable with them and have their keys set up.

I built this mostly to cover a few specific gaps that things like 
Bitwarden, LastPass or plain OpenSSL don't really solve:

No setup, no accounts. Nothing to register, no keys to manage 
beforehand. It just works the moment you open the link, even with 
people who aren't technical or don't have the tools installed.

Nothing is ever stored, not even encrypted. Password managers 
still keep your encrypted blob on their servers somewhere. Here 
there's genuinely nothing sitting on disk at any point, so 
there's nothing to leak later, no traces.

Services like Bitwarden Send put the decryption key in the URL 
fragment. Fine, except you still have to send that link over some 
channel, and if that channel isn't secure you're back where you 
started. Here the exchange itself is what makes the channel 
secure, you're not relying on the transport being trustworthy.

Also turns out to be handy just for yourself. With the CLI you 
can pipe a secret, a .env file, a db dump, whatever, from a 
remote server to your laptop (or the other way or server to 
server, when they can't reach each other directly) without 
setting up anything.

Andrea


More information about the Digitalmars-d-announce mailing list