Cryptographic Specification

Zero-Knowledge Security Architecture

VanishShare is built on a fundamental principle: our servers should never possess the mathematical capability to decrypt your data. Here is how we enforce zero-knowledge isolation.

The Three Cryptographic Pillars

🧮

1. Web Crypto AES-256-GCM

Encryption is executed in the browser sandbox using the hardware-accelerated W3C Web Crypto API. Each secret receives a cryptographically secure 256-bit symmetric key and a unique 96-bit initialization vector (IV) to prevent replay and ciphertext manipulation.

🔗

2. URL Hash Key Isolation

Per RFC 3986 Section 3.5, the URI fragment identifier (the portion following #) is handled exclusively client-side. Web browsers strictly refuse to send hash fragments in HTTP requests. Thus, the decryption key never touches our web servers or proxy access logs.

🛡️

3. PBKDF2 & Key Wrapping

When an optional passphrase is set, the 256-bit master key is wrapped using PBKDF2 with HMAC-SHA-256 and 100,000 iterations with a unique cryptographic salt. An additional AES-GCM verifier ensures wrong passphrases fail client-side before any request is dispatched.

End-to-End Cryptographic Flow

Step-by-step lifecycle from encryption to permanent destruction:

1

Key Generation

window.crypto.subtle.generateKey yields an exportable AES-GCM 256-bit symmetric master key (K_master).

2

Data Encryption

Payload text and file bytes are encrypted with K_master and a random 12-byte initialization vector (IV). File metadata (original name, MIME type, size) is encrypted in a parallel ciphertext structure.

3

Server Storage (Ciphertext Only)

Only the encrypted ciphertext and expiration metadata (TTL, max download limits) are transmitted to the server. The raw key is appended to the browser link as #key=... and retained only by the sender.

4

MFA & Local Decryption

Recipient navigates to the URL. If email restriction is active, the recipient must confirm a one-time passcode. The browser then extracts K_master from the hash fragment and decrypts the ciphertext locally.

5

Irreversible Destruction

Upon download completion or TTL expiration, the database document and encrypted storage objects are hard-deleted. No snapshots or backups retain expired data.

Threat Model & Mitigations

Threat VectorPotential ImpactVanishShare Mitigation
Compromised Database / StorageAttacker acquires all stored rowsAttacker only obtains AES-256 ciphertexts. Decryption is mathematically infeasible without client keys.
Network Eavesdropping / ISP InspectionAttacker monitors HTTP / TLS trafficTLS 1.3 in transit + hash fragment keys are never included in HTTP request lines.
Server Rogue Admin / Insider ThreatAdmin inspects memory & logsPlaintext and decryption keys are never transmitted to or processed by the server.
Brute-Force Passphrase AttackAttacker guesses password repeatedlyPBKDF2 with 100,000 iterations slows offline dictionary attacks exponentially.

Experience Zero-Knowledge Sharing

Create an encrypted, self-destructing secret in seconds.

Generate Encrypted Secret