dead-drop

A transparent envelope for secrets.

donkeyx

How it works

The secret is encrypted before it is uploaded. The server only ever stores ciphertext. The key lives in the URL fragment after # — browsers do not send that to the server.

Three ways

curl -fsSL https://raw.githubusercontent.com/donkeyx/dead-drop/master/install.sh | sh
dead-drop get -out secret.txt 'https://drop.donkeyx.dev/s/ID#KEY'

Pin a tag instead of master if you do not want to pipe latest. Checksums are verified. go install github.com/donkeyx/dead-drop/cmd/dead-drop@latest if you already have Go.

What to trust

Do not use this for anything where you cannot accept a compromised browser, server, or deploy.

Back to dead-drop · v0.1.10