Browser-side decryption for Age-encrypted share links
programming.dev
Browser-side decryption for Age-encrypted share links
I built a small open-source web app that lets people share Age-encrypted files using ordinary web hosting. The encrypted file can be hosted at any HTTPS URL, including a public or pre-signed URL for an S3-compatible object store. Decryption happens locally in the recipient’s browser. Source: https://github.com/parsimonit/web-age-stream-decryptor [https://github.com/parsimonit/web-age-stream-decryptor] Demo: https://decrypt-app.zebrastream.io/ [https://decrypt-app.zebrastream.io/] The encrypted file stays on the existing server. The recipient opens a share link, and the file is decrypted locally in the browser for viewing or downloading. There’s no decryption backend. The link contains the file URL and Age passphrase in the URL fragment, so the passphrase is not sent in the HTTP request. The complete link is still a bearer secret: anyone who gets it can decrypt the file. I’m interested in feedback from people familiar with privacy tools and threat modeling: - Is this useful compared with existing encrypted file-sharing tools? - Are there important browser or URL-leakage risks I should document? - Does the “static frontend + arbitrary encrypted object storage” model seem worthwhile? - Should rendering decrypted HTML be disabled or treated as an unsafe feature? Current limitations include buffering large files in memory and the possibility of script execution when decrypted HTML is rendered.
0 comments
No comments yet.