Send Self Destructing E-mails
fade.li
fade.li
2) Options on the right "Show Original"
3) Copy the URL that goes like: http://content.fade.li/selcouth/... to a new tab
4) Save image as
5) ...
6) Profit!
For added fun, somebody please go and register unfade.li, if you forward a mail there, it OCR scans the image and sends you back the text.
P.S. sending email as images is one of the most stupid ideas that seems to keep cropping up. It's not in any way making it impossible to get at the email, but it just makes it extremely inconvenient to reply inline, or for differently abled people to read your mail.
http://www.faststone.org/FSCapturerDownload.htm
but an old version (5.3) that always worked well for me is free:
> Your email's content is encrypted using banking-grade algorithms (256 AES) and securely stored on our servers.
> No traces.
> We were also growing tired of news about privacy issues and claims of government reading our emails behind our backs… it all seemed very Orwellian
It feels like you're kind of suggesting these things are actually secure.
Upon opening, the content 'fades-out' and fade.li assure us that they delete the content from their systems.
/me tries with disposable account
Aha, it renders the mail content as images. A bunch of basic HTML with the GIFs inline, I used wget to pull them down but the metadata is corrupted. I'll poke at them...
Aha2: animated GIF. Frame-by-frame 'writing' of the e-mail, then blanking-out. Presumably they delete the GIF from their server when it has been served once.
Here's one ( safe for work! )
But yeah, ultimately it's a losing game because you're trusting the client not to be compromised.
allows you to replay a request, complete with all cookies and the exact same headers.
yeah, aware this isn't what's wanted here, single request image etc etc ... but relevant.
Those headers can vary from machine to machine even when using the same browser. So you'd have a huge amount of testing, plus the big risk of braking legitimate requests. I just cant see how you could pull that off successfully.
> But yeah, ultimately it's a losing game because you're trusting the client not to be compromised.
Totally. Even if your solution did work, it's trivial to break again as you just add the appropriate headers to wget / curl as well as changing the user agent string.
First rule of piracy people, if you can read, see or hear it then you can copy it.
As far as ideas, I'm actually thinking the complete opposite. Going on record - like an 3rd party service that proves that you sent an email to a person at a certain date and time in case of a later dispute. e.g.
youremail@google.com.prove.it
The common complaint that it is impossible to self destruct data is obvious to most people. If it is technically impossible to make something un-shareable then the only thing you have left is social convention.
Anyone else find the landing page a little bit overwhelming for such a small app? All the pictures of people having a great time seem a little over the top?
EDIT: Looking through their privacy statement:
"Hence messages are to be sent at the risk of the user. Information such as messages, time, date, name of the receiver and sender are also logged by us. We also collect and use aggregated or de-identified information."
IANAL but that looks to me that they are storing messages?
Also I am supposed to trust (yet) another third party who hasn't got a neck in the game to keep my privacy?
Sorry I don't get it.
"Hey, could you resend that? I opened it and then had to switch to another tab for a few seconds, but when I got back the message was already 90% gone"
It's not secure, it's not accessible and I fail to see how it protects privacy of defeat surveillance in any way, actually all your emails are now belonging to another third party, namely fade.li.
oh and the emails and not even self destructing.
Use openGPG instead.