Web shareable read links #67

Closed
opened 2026-09-21 18:06:06 +01:00 by cruelacid · 1 comment
Owner

Part of #37.

What Relay does

Not shipped. "Web content access — browser access with shareable links" sits
under Considering.

Why this is hard for us and easy for them

Their server holds plaintext, so a share link is a URL and a permission check.
Ours cannot be: the server holds ciphertext and no keys, so a link must carry
the key material
— typically in the URL fragment, which never reaches the
server.

That is a well-understood construction, but it changes the threat model in ways
docs/security-model.md currently does not cover: a link in someone's browser
history or a chat log is the key. Anyone who has it can read, and rotation means
re-sharing.

If it is ever built

  • Key in the fragment, never in the path or query.
  • A viewer that decrypts in the browser, which means publishing a second piece
    of client code that must be as auditable as the plugin
    — see the
    unminified-client issue.
  • An expiry, and a way to revoke that actually works.

Recommendation

Do not build this speculatively. It is the one item on the list that could
quietly weaken the central claim, and it should only be taken with the security
model rewritten first.

Risk

risk:additive mechanically; the real cost is to the security model.

Part of #37. ## What Relay does **Not shipped.** "Web content access — browser access with shareable links" sits under **Considering**. ## Why this is hard for us and easy for them Their server holds plaintext, so a share link is a URL and a permission check. Ours cannot be: the server holds ciphertext and no keys, so **a link must carry the key material** — typically in the URL fragment, which never reaches the server. That is a well-understood construction, but it changes the threat model in ways `docs/security-model.md` currently does not cover: a link in someone's browser history or a chat log is the key. Anyone who has it can read, and rotation means re-sharing. ## If it is ever built - Key in the fragment, never in the path or query. - A viewer that decrypts in the browser, which means **publishing a second piece of client code that must be as auditable as the plugin** — see the unminified-client issue. - An expiry, and a way to revoke that actually works. ## Recommendation Do not build this speculatively. It is the one item on the list that could quietly weaken the central claim, and it should only be taken with the security model rewritten first. ## Risk `risk:additive` mechanically; the real cost is to the security model.
Author
Owner

Moved to the Vikunja board as NEC-44: https://projectron.nerchure.com/tasks/44

Moved to the Vikunja board as **NEC-44**: https://projectron.nerchure.com/tasks/44
Sign in to join this conversation.
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
Nectenda/nectenda#67
No description provided.