Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm not sure that is true. If the link automatically decrypts the paste then you could use server logs to get the plaintext of the document.


From my understanding, the link contains 2 parts -- paste ID, and decryption key _following_ a "#". Assuming the latter isn't going into the server logs (I believe the fragment identifier isn't sent in headers at all, unless there's JS on the page to tell the server about it), the actual decryption seems to be taking place via javascript (as well as the encryption to begin with), and therefore the encryption key has no reason to be sent to the server at any point.


Someone didn't read the project page ...

See the section "When opening a ZeroBin URL: "


see: http://sebsauvage.net/wiki/doku.php?id=php:zerobin

the "pasting" and "opening" sections cover this




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: