73 HB9ERY QSL

compare secure pastebin available projects

# Requirements

  • It must encrypt on the client side (js code) the contents before sending to the server. Server has no way of reading decrypted contents.
  • Project must be actively maintained.
  • Small footprint: we don’t want a whole complex JVM for such task.
  • We can select expiry.
  • We can set a password: The URL contains the key, if url is stolen, contents are readable. A password provides 2FA.
  • Syntax highlighting is nice to have but mandatory
  • Can we use from shell? like cli client

# Candidates

Name/URL client-side encryption maintained language expiry password syntax highlighting cli client comment
0bin aes256 not actively, last commit Mar 2021 js, python yes no yes no seems abandonned: github comment says We cannot accept contributions for the moment, and will ignore PR.
paaster aes356-cbc yes, last commit 21.08.2022 js, python yes no yes yes documentation about client-side and server-side secrets are confusing somehow.. it copy-paste bin, not an editor
privatebin aes256-gcm yes actively js, php yes yes yes no QR code generation, file upload, discussions board
purritobin yes no, last commit 11 Apr 2021 c++ yes no no yes made for cli friendly and minimalistic

## 0bin

It surely was an interesting project. However, the project seems nearly abandonned. There is no cli client. There is no password protection.

Zoom E2EE

End-to-end encryption (E2EE) means that data is encrypted between the different endpoints. No intermediary party can decrypt it and thus, private communication is achieved.

After a long long list of security failures, bad programming, poor design choices. Zoom made lots of efforts to fix several serious issues and recently brought finally the E2EE feature.

General meeting uses a meeting key to protect communication transit with aes-256-gcm. The key is distributed, by Zoom servers, to each joining participiant. It uses a KDF (HMAC) including cleartext stream id.

Traçage de contacts par ordiphone

Après avoir analysé différents protcoles proposés pour une apllication mobile, qui permet de consolider les données au bénéfice exclusif des épidémiologistes et de prévention de chaîne de risque, pour les utilisateurs de cette application, je tiens à résumer ici celui qui me semble le plus strictement construit dans l’intérêt commun de la santé publique et de la vie privée de ses utilisateurs.

Je ne présenterai pas les autres qui sont certes intéressants mais, à mon sens, n’offrent pas les mêmes garanties, en cherchant le meilleur équilibre, tel que le décrit le DP-3T.