How it works
The secret is encrypted before it is uploaded. The server only ever stores ciphertext. The key lives in the URL fragment after # — browsers do not send that to the server.
Three ways
- Browser — this site. Fast. You trust the JavaScript we served you.
- CLI — encrypt on your machine. Use it to
geta drop, orputto a server you run if you do not trust this origin's JS. Hosted create is browser-only (human check). - Your own instance — same protocol, Docker or Helm. Then the CLI talks to you.
curl -fsSL https://raw.githubusercontent.com/donkeyx/dead-drop/master/install.sh | sh
dead-drop get -out secret.txt 'https://drop.donkeyx.dev/s/ID#KEY'
Pin a tag instead of master if you do not want to pipe latest. Checksums are verified. go install github.com/donkeyx/dead-drop/cmd/dead-drop@latest if you already have Go.
What to trust
- The source is public at github.com/donkeyx/dead-drop.
- Burn-after-read is atomic: one successful download consumes a drop.
- Client-side encryption is not a promise that this host is harmless. Verify the code or run your own.
Do not use this for anything where you cannot accept a compromised browser, server, or deploy.
Back to dead-drop · v0.1.10