Live data from Hacker News

Why I created scrt.link

blog.stophe.com

1–10 of 43 posts

Re: Why I created scrt.link

#2
I just created and consumed a secret message. It seemed to work. Plus, I didn't have to create an account. Easy to use. I also love the name.

I noticed in the FAQ you refer to your three secret types as text, redirect, and neogram. In other places you seem to call redirect "link". Could be a naming consistency fix.

Features like delete after N visits or by X date might be useful too.

I'm a little confused about the use case. Maybe I'm boring, but who would I need to send a scrt.link to? I can think of bad use cases, for example maybe a botnet could propagate messages through this, or share credentials that would change after using or something. I can't really think of other use cases though without going a bit unrealistic.

I read the FAQ about why I should use it. I'm not sure it's great for credentials because if they aren't continually going to be available through the link, the other party will need to copy them.

If I'm doing something with minor security concerns, e.g. sharing the Netflix password, I'm just going to send it over text or whatever. If it gets compromised I'll just reset and change it. If I'm doing something with significant security concerns, e.g. sharing credential to access a production database at work, then I'm obviously not going to use this due to trustworthiness concerns.

Re: Why I created scrt.link

#3

I just created and consumed a secret message. It seemed to work. Plus, I didn't have to create an account. Easy to use. I also love the name. I noticed in the FAQ you refer to your three secret types as text, redirect, and neogram. In other places you seem to call redirect "link". Could be a naming consistency fix. Features like delete after N visits or by X date might be useful too. I'm a little confused about the u…

someone in an abusive relationship?

whistleblower?

plenty of scenarios

Re: Why I created scrt.link

#4
I’m always wary of consumer services that specifically target secrecy and encryption. How many of those “lockbox” photo apps are just syphons into the developer’s server?

“We’ll encrypt the file, trust us.”

This message can only come from an already-trusted party. Mozilla had an identical service to this except it was for files (Firefox Send) and that one I could trust.

Re: Why I created scrt.link

#5

I just created and consumed a secret message. It seemed to work. Plus, I didn't have to create an account. Easy to use. I also love the name. I noticed in the FAQ you refer to your three secret types as text, redirect, and neogram. In other places you seem to call redirect "link". Could be a naming consistency fix. Features like delete after N visits or by X date might be useful too. I'm a little confused about the u…

someone in an abusive relationship? whistleblower? plenty of scenarios

I don't understand. If I'm in an abusive relationship or am a whistleblower why would I want to send a read-once message? Why is this better than pastebin? (Which, incidentally has this as an optional feature)

Re: Why I created scrt.link

#6

Earlier quoted context omitted.

someone in an abusive relationship? whistleblower? plenty of scenarios

I don't understand. If I'm in an abusive relationship or am a whistleblower why would I want to send a read-once message? Why is this better than pastebin? (Which, incidentally has this as an optional feature)

If you trust the recipient, but there's a chance that they will be threatened and asked/forced to reveal the message that you sent them, they may appreciate a mechanism that gives them plausible deniability.

Obviously a recipient could make a copy of any disappearing message that they receive if they really wanted to, so you do need to actually trust them. It's less for your security, and more for theirs.

Re: Why I created scrt.link

#7
If I pasted a scrt.link to a friend over WhatsApp or Messenger, and the little link preview pops up, does that trigger a visit count, resulting in the message already being destroyed before the friend gets to click on it?

Re: Why I created scrt.link

#8

I’m always wary of consumer services that specifically target secrecy and encryption. How many of those “lockbox” photo apps are just syphons into the developer’s server? “We’ll encrypt the file, trust us.” This message can only come from an already-trusted party. Mozilla had an identical service to this except it was for files (Firefox Send) and that one I could trust.

If I wrote something like this, I'd try to be as transparent as I could be as to who I was, and how you could contact me. Hopefully that would create some small level of trust.

--

As an aside, I know you are trying to be funny, but your username is tad offensive.

Re: Why I created scrt.link

#9

If I pasted a scrt.link to a friend over WhatsApp or Messenger, and the little link preview pops up, does that trigger a visit count, resulting in the message already being destroyed before the friend gets to click on it?

Good question! Bot traffic from common apps/services is beeing blocked. But let me know if you run into a problem. C.

Re: Why I created scrt.link

#10
post #6

Earlier quoted context omitted.

I don't understand. If I'm in an abusive relationship or am a whistleblower why would I want to send a read-once message? Why is this better than pastebin? (Which, incidentally has this as an optional feature)

If you trust the recipient, but there's a chance that they will be threatened and asked/forced to reveal the message that you sent them, they may appreciate a mechanism that gives them plausible deniability. Obviously a recipient could make a copy of any disappearing message that they receive if they really wanted to, so you do need to actually trust them. It's less for your security, and more for theirs.

yup, also you can trust the person but maybe not trust their long term security. the short the lifespan the small surface of attack.
Post reply on HN