Hacker News new | ask | show | jobs
by SamuelAdams 2661 days ago
> The url effectively contains the decryption key, so the web server could be set to capture the urls and decrypt files.

If that's the case, I think setting a passphrase should be mandatory. Proxy servers are extremely common at every workplace. Since they probably log all requests, they will capture all keys in the URL.

1 comments

The key is in the fragment and thus is not sent to any server.