I thought urls weren't encrypted in HTTPS? Am I missing something?
I thought urls weren't encrypted in HTTPS? Am I missing something?
So even if the URL isn't encrypted in HTTPS (it is though), it wouldn't matter.
The problem with URLs is that a lot of products will log the URL to disk, and many operators forget or aren't aware they might need to have security plans around data in the logs.
This is the reason not to put authentication tokens into URLs for example.
When the state users want to bookmark or share literally is the state that's encrypted anyway this mismatch isn't a threat. If I send you the URL for this drawing of a cat and then I'm astonished you can now see the drawing of the cat I've got real problems technology can't fix.
Having the key in the url seems insanely insecure to me.
The threat model the author tried to work around is not the user dumbly compromising their own work. The author wants to prevent proprietary and PII data from being stored on their own server. End-to-end encryption significantly reduces the author's potential liability hosting something like this in case something goes wrong.
I'll hit the URL bar and hit control-C. That's way better than any javashit which wants to touch my clipboard.
Copying the current URL also copies the key in that case. Now I'm accidentally sharing my encryption information with another user.
https://en.wikipedia.org/wiki/Server_Name_Indication#Securit...
Spend some time with wireshark running while you visit “google.com” in a web browser and you’ll get a better intuition on the topic.