neverstored: hand over a secret without leaving traces
Andrea Fontana
nospam at example.org
Wed Sep 16 10:42:50 UTC 2026
On Wednesday, 16 September 2026 at 08:20:25 UTC, Dejan Lekic
wrote:
> On Monday, 14 September 2026 at 15:07:37 UTC, Andrea Fontana
> wrote:
>
>>
>> Let me know what you think!
>
> Nice! Perhaps good for a company, though most companies
> nowadays use stuff like LastPass which has this functionality
> out of box. I like the idea and simplicity!
>
> Personally I just use OpenSSL or GPG (for bigger files),
> encrypt file with my colleague's public key, and send encrypted
> file to her/him via email. :) This is rare anyway (happens once
> or twice a year), so OpenSSL works for me.
GPG/OpenSSL are definitely great for those who are already
comfortable with them and have their keys set up.
I built this mostly to cover a few specific gaps that things like
Bitwarden, LastPass or plain OpenSSL don't really solve:
No setup, no accounts. Nothing to register, no keys to manage
beforehand. It just works the moment you open the link, even with
people who aren't technical or don't have the tools installed.
Nothing is ever stored, not even encrypted. Password managers
still keep your encrypted blob on their servers somewhere. Here
there's genuinely nothing sitting on disk at any point, so
there's nothing to leak later, no traces.
Services like Bitwarden Send put the decryption key in the URL
fragment. Fine, except you still have to send that link over some
channel, and if that channel isn't secure you're back where you
started. Here the exchange itself is what makes the channel
secure, you're not relying on the transport being trustworthy.
Also turns out to be handy just for yourself. With the CLI you
can pipe a secret, a .env file, a db dump, whatever, from a
remote server to your laptop (or the other way or server to
server, when they can't reach each other directly) without
setting up anything.
Andrea
More information about the Digitalmars-d-announce
mailing list