nullsec
server-blind encrypted paste
About
nullsec is a minimalist encrypted paste service. The server never receives the encryption key or plaintext.
Features
- AES-256-GCM encryption
- Client-side key generation
- Key in URL fragment only (#key)
- Server-blind architecture
- Read once support
- Expiration: 1 hour – 30 days
- Strict CSP and security headers
- No user accounts
- No logs. No IP logging.
- Rate limited
- Automatic cleanup every 5 minutes
- Static first-party assets only
How it works
Your browser encrypts the text locally. The encrypted data and IV are sent to the server. The key stays in the fragment and is never sent over HTTP.
Contact
nevsky.null@proton.me
Community
nullsec by NevskyNull — XSS.mx (DaMaGeLaB)
Security