Thank you to everyone who took the time to review QuickClip and give honest feedback.
I spent the day going through everything and fixing the issues that were pointed out, especially around security.
You were right. The concerns were valid, and they’re now addressed.
1. Shared encryption key (Retr0id's main issue):
Problem: All users shared one encryption key, so any user could decrypt any other user's data.
Fix: Each user now has a unique encryption key derived via PBKDF2 from master key + user ID (10,000 iterations). Old items encrypted with the shared key are detected during decryption and automatically re-encrypted in the background with the new per-user key. Backward compatibility is maintained during the migration.
2. Public image access (Retr0id's second issue):
Problem: Images were publicly accessible without authentication.
Fix: Images now use signed URLs that expire after 1 year. The app automatically converts any public URLs to signed URLs. Storage bucket policies restrict access to user-specific folders.
3. Storage enumeration (foltik's issue):
Problem: Could enumerate all user uploads with a sign-up token.
Fix: Storage policies now restrict folder access by user ID. Still reviewing listing permissions to prevent enumeration.
4. E2EE misrepresentation:
Problem: Marketing claimed "end-to-end encrypted" but it wasn't true E2EE.
Fix: Added a /data-security page that explains:
It's server-side encryption with per-user keys, not true E2EE
Why server-side encryption was chosen (seamless cross-device sync)
5. Transparency issues:
Problem: No information about how data is handled before signup.
Fix: Added /data-security page with details. Link added to footer. Removed the footer joke that hurt trust.
6. Other fixes:
Rate limits adjusted for encryption/decryption operations
Background re-encryption for old items
Proactive signed URL conversion for images
What's still being worked on:
Storage bucket listing permissions (enumeration prevention)
Adding screenshots to landing page
FAQ section
Considering open source (evaluating)
I appreciate the security review. The app is more secure now, and I'm committed to transparency about what it does and doesn't do. Check /data-security for the full explanation.