<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/" xmlns:content="http://purl.org/rss/1.0/modules/content/">

  <channel>
    <title>73 HB9ERY QSL</title>
    <link>/</link>
    <description>Recent blog posts on 73 HB9ERY QSL</description>
    
    <generator>Hugo (https://gohugo.io)</generator>
    
    <language>en-gb</language>
    
    <managingEditor>jma@mbuf.net (jma)</managingEditor>
    
    <webMaster>jma@mbuf.net (jma)</webMaster>
    
    <lastBuildDate>Sat, 24 Sep 2022 00:00:00 Z</lastBuildDate>
    
    <atom:link href="/tags/pastebin/index.xml" rel="self" type="application/rss+xml" />
    

    <item>
      <title>compare secure pastebin available projects</title>
      <link>/posts/pastebin/</link>
      <pubDate>Sat, 24 Sep 2022 00:00:00 Z</pubDate>
      
      <author>jma@mbuf.net (jma)</author>

      
      
      
      

      <description>
       # Requirements It must encrypt on the client side (js code) the contents before sending to the server. Server has no way of reading decrypted contents. Project must be actively maintained. Small footprint: we don&amp;amp;rsquo;t want a whole complex JVM for such task. We can select expiry. We can set a password: The URL contains the key, if url is stolen, contents are readable. A password provides 2FA. Syntax highlighting is nice to have but mandatory Can we use from shell? like cli client # Candidates Name/URL client-side encryption maintained language expiry password syntax highlighting cli client comment 0bin aes256 not actively, last commit Mar 2021 js, python yes no yes no seems abandonned: github comment says We cannot accept contributions for the moment, and will ignore PR. paaster aes356-cbc yes, last commit 21.08.2022 js, python yes no yes yes documentation about client-side and server-side secrets are confusing somehow.. it copy-paste bin, not an editor privatebin aes256-gcm yes actively js, php yes yes yes no QR code generation, file upload, discussions board purritobin yes no, last commit 11 Apr 2021 c&#43;&#43; yes no no yes made for cli friendly and minimalistic ## 0bin It surely was an interesting project. However, the project seems nearly abandonned. There is no cli client. There is no password protection.

      </description>
      <content:encoded>&lt;h2 id=&#34;requirements&#34; &gt;
&lt;div&gt;
    &lt;a href=&#34;#requirements&#34;&gt;
        #
    &lt;/a&gt;
    Requirements
&lt;/div&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;It must encrypt on the client side (js code) the contents before sending to the server. Server has no way of reading decrypted contents.&lt;/li&gt;
&lt;li&gt;Project must be actively maintained.&lt;/li&gt;
&lt;li&gt;Small footprint: we don&amp;rsquo;t want a whole complex JVM for such task.&lt;/li&gt;
&lt;li&gt;We can select expiry.&lt;/li&gt;
&lt;li&gt;We can set a password: The URL contains the key, if url is stolen, contents are readable. A password provides 2FA.&lt;/li&gt;
&lt;li&gt;Syntax highlighting is nice to have but mandatory&lt;/li&gt;
&lt;li&gt;Can we use from shell? like cli client&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;candidates&#34; &gt;
&lt;div&gt;
    &lt;a href=&#34;#candidates&#34;&gt;
        #
    &lt;/a&gt;
    Candidates
&lt;/div&gt;
&lt;/h2&gt;
&lt;table&gt;
	&lt;thead&gt;
			&lt;tr&gt;
					&lt;th&gt;Name/URL&lt;/th&gt;
					&lt;th&gt;client-side encryption&lt;/th&gt;
					&lt;th&gt;maintained&lt;/th&gt;
					&lt;th&gt;language&lt;/th&gt;
					&lt;th&gt;expiry&lt;/th&gt;
					&lt;th&gt;password&lt;/th&gt;
					&lt;th&gt;syntax highlighting&lt;/th&gt;
					&lt;th&gt;cli client&lt;/th&gt;
					&lt;th&gt;comment&lt;/th&gt;
			&lt;/tr&gt;
	&lt;/thead&gt;
	&lt;tbody&gt;
			&lt;tr&gt;
					&lt;td&gt;&lt;a href=&#34;https://github.com/Tygs/0bin&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;0bin&lt;/a&gt;&lt;/td&gt;
					&lt;td&gt;aes256&lt;/td&gt;
					&lt;td&gt;not actively, last commit Mar 2021&lt;/td&gt;
					&lt;td&gt;js, python&lt;/td&gt;
					&lt;td&gt;yes&lt;/td&gt;
					&lt;td&gt;no&lt;/td&gt;
					&lt;td&gt;yes&lt;/td&gt;
					&lt;td&gt;no&lt;/td&gt;
					&lt;td&gt;seems abandonned: github comment says We cannot accept contributions for the moment, and will ignore PR.&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;&lt;a href=&#34;https://github.com/WardPearce/paaster&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;paaster&lt;/a&gt;&lt;/td&gt;
					&lt;td&gt;aes356-cbc&lt;/td&gt;
					&lt;td&gt;yes, last commit 21.08.2022&lt;/td&gt;
					&lt;td&gt;js, python&lt;/td&gt;
					&lt;td&gt;yes&lt;/td&gt;
					&lt;td&gt;no&lt;/td&gt;
					&lt;td&gt;yes&lt;/td&gt;
					&lt;td&gt;yes&lt;/td&gt;
					&lt;td&gt;documentation about client-side and server-side secrets are confusing somehow.. it copy-paste bin, not an editor&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;&lt;a href=&#34;https://privatebin.info/&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;privatebin&lt;/a&gt;&lt;/td&gt;
					&lt;td&gt;aes256-gcm&lt;/td&gt;
					&lt;td&gt;yes actively&lt;/td&gt;
					&lt;td&gt;js, php&lt;/td&gt;
					&lt;td&gt;yes&lt;/td&gt;
					&lt;td&gt;yes&lt;/td&gt;
					&lt;td&gt;yes&lt;/td&gt;
					&lt;td&gt;no&lt;/td&gt;
					&lt;td&gt;QR code generation, file upload, discussions board&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;&lt;a href=&#34;https://github.com/PurritoBin/PurritoBin&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;purritobin&lt;/a&gt;&lt;/td&gt;
					&lt;td&gt;yes&lt;/td&gt;
					&lt;td&gt;no, last commit 11 Apr 2021&lt;/td&gt;
					&lt;td&gt;c++&lt;/td&gt;
					&lt;td&gt;yes&lt;/td&gt;
					&lt;td&gt;no&lt;/td&gt;
					&lt;td&gt;no&lt;/td&gt;
					&lt;td&gt;yes&lt;/td&gt;
					&lt;td&gt;made for cli friendly and minimalistic&lt;/td&gt;
			&lt;/tr&gt;
	&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id=&#34;0bin&#34; &gt;
&lt;div&gt;
    &lt;a href=&#34;#0bin&#34;&gt;
        ##
    &lt;/a&gt;
    0bin
&lt;/div&gt;
&lt;/h3&gt;
&lt;p&gt;It surely was an interesting project.
However, the project seems nearly abandonned.
There is no cli client.
There is no password protection.&lt;/p&gt;
&lt;p&gt;I do not recommend this project anymore.&lt;/p&gt;
&lt;h3 id=&#34;privatebin&#34; &gt;
&lt;div&gt;
    &lt;a href=&#34;#privatebin&#34;&gt;
        ##
    &lt;/a&gt;
    Privatebin
&lt;/div&gt;
&lt;/h3&gt;
&lt;p&gt;Actively maintained project.
Client-side is managed by javascript and server-side with PHP.
Interesting features: password protection, QR code generation, discussion board, file attachments.
No cli client is the missing feature.&lt;/p&gt;
&lt;p&gt;Interesting to use for common case. Good project.&lt;/p&gt;
&lt;h3 id=&#34;paaster&#34; &gt;
&lt;div&gt;
    &lt;a href=&#34;#paaster&#34;&gt;
        ##
    &lt;/a&gt;
    Paaster
&lt;/div&gt;
&lt;/h3&gt;
&lt;p&gt;Actively maintained project.
Client-side is managed by javascript and server-side with Python.
Interesting features: direct bin for copy-paste, no editing. API for client, expiry selection.&lt;/p&gt;
&lt;p&gt;Recommended where cli client is of a good need.
Fewer features than privatebin, but if cli client and API integration is your need, get this one.&lt;/p&gt;
&lt;h4 id=&#34;purritobin&#34; &gt;
&lt;div&gt;
    &lt;a href=&#34;#purritobin&#34;&gt;
        ###
    &lt;/a&gt;
    Purritobin
&lt;/div&gt;
&lt;/h4&gt;
&lt;p&gt;Not really an active project, while a c++ server and client exist.
Very minimalistic application, no password, no file attachment.
json api exist for the client and encryption is optionnal.&lt;/p&gt;
&lt;p&gt;Give a try but not actively developped is missing sign of evolution.&lt;/p&gt;
</content:encoded>
      
      <category>pastebin</category>
      
      <category>security</category>
      
      
      <category>security</category>
      
      <guid isPermaLink="true">/posts/pastebin/</guid>
    </item>
    
  </channel>
</rss>
