1
0 Comments

I built a pastebin where I literally cannot read your data - here's how

ScorchPad works differently. Your browser generates a 256-bit key, encrypts your text with AES-256-GCM locally, and sends only the encrypted blob to the server. The key lives in the URL fragment -browsers never include that in HTTP requests. So my server never sees it. Ever.

What that means practically:

  • I cannot read your pastes

  • I cannot comply with data requests - there's nothing to hand over

  • I cannot identify you by IP - raw IPs are never stored

A few implementation details I'm proud of:

  • Burn-after-reading is atomic via a Lua script on Redis - race-condition proof

  • PBKDF2-SHA256 at 310,000 iterations for password-protected pastes

  • Monthly warrant canary published

  • Fully open source

I also document my own weaknesses openly - including the JS supply chain risk. Because honest threat modeling matters more than marketing.

Would love feedback from the community - especially on the threat model.

posted toAvatar for product Scorchpad
Scorchpad