FAQ - Frequently Asked Questions
Why did we build this site?
In our day jobs, we found it quite challenging to securely share passwords for protected files. Do you send them in an email, or an SMS? Do you use secure gateways, or try and use the share function in a Cloud password manager? Are Cloud password managers even safe in this day and age?
In the end, we decided to build our own tool that could be used to securely and anonymously share passwords and other secrets.
Just how secure is this site?
We would like to think quite secure! Here are some of the steps we take to keep our site, and the secrets it holds, as secure as possible.
- We use various Firewalls (physical and WAF - Web Application Firewall) to protect our servers
- We keep our servers regularly patched with the latest software and security releases, and only use LTS (Long Term Support) Operating System Releases
- All secrets are encrypted before they are stored, and we regularly review the strength of the encryption used, to ensure it is the best possible level
- Secrets can be further protected by your own passphrase, which is recommended. This ensures no one but you and your intended recipient can view the secret
- Our servers are heavily locked down, to restrict access to only authorised users
- We make this site as "anonymous" as possible. We don't capture any extra data from you other than what is necessary
- Secrets are short lived by nature: 24 hours by default, and can only be viewed once
Can I send pictures and other media, or just text?
To keep the site as secure as possible, we restricted the usage of this site to text only. This also helps keep the site as lightweight as possible.
Sharing pictures and other media can also have other legal and security issues, which we did not want to factor in. For example, media files can contain metadata that can disclose details about where it was captured and by whom. We also wanted to avoid any Copyright issues with illegal file-sharing.
How long do you keep a secret?
Secrets are only kept for 24 hours.
What is the maximum secret/message size?
The current maximum message length is 250 characters.
Can I have longer messages/longer expiry time?
If this site is popular, we may look at introducing other "tiers" which can provide extra features.
I'm still not sure about using your site?
No problem! There's no pressure to use our site. It's a tool that we built to help us with our own challenges in sharing secrets, and thought others might find it useful too.