docs: clarify how/where encryption key is inside an URL

In order to clarify things like raised in https://github.com/PrivateBin/PrivateBin/pull/1759#discussion_r2746115299

So people are not too concerned about bots...
This commit is contained in:
rugk
2026-01-30 13:47:22 +01:00
committed by GitHub
parent c43c5a19d6
commit 45719f6b7b

View File

@@ -43,8 +43,10 @@ features.
[DANE](https://en.wikipedia.org/wiki/DNS-based_Authentication_of_Named_Entities)
record.
- The "key" used to encrypt the paste is part of the URL. If you publicly post
the URL of a paste that is not password-protected, anyone can read it.
- The "key" used to encrypt the paste is part of the URL (in
[the fragment part separated by the `#`](https://en.wikipedia.org/wiki/URL#fragment)).
If you publicly post the URL of a paste that is not password-protected, anyone
can read it.
Use a password if you want your paste to remain private. In that case, make
sure to use a strong password and share it privately and end-to-end-encrypted.