Privacytools.io: Ghostbin

Created on 16 Mar 2018  ยท  6Comments  ยท  Source: privacytools/privacytools.io

Ghostbin is not really secure, because after creating an encrypted paste, it's possible to access it with javascript disabled, which means the content is not decrypted in the user's browser. Also, it requires cookies to even work at all, which shouldn't be needed.

Most helpful comment

Just FYI:
ghostbin.com runs outdated Apache 2.4.18 and outdated OpenSSH 7.2 P2. The security of the whole server setup isn't very exemplary. Furthermore, the TLS configuration supports insecure RC4 for encryption and weak cipher suites.

All 6 comments

Open Source Ghostbin Alternatives - AlternativeTo.net
https://alternativeto.net/software/ghostbin/?license=opensource

It can be self-hosted, though, if you're concerned about server-side security. But yeah, we're just recommending the main server.

I don't consider that secure, but maybe it's just me...
Regardless, Ghostbin should be the third option in the Paste Services section and not the first, and maybe it should be mentioned in the notes that encryption/decryption is not done in the browser.

Just FYI:
ghostbin.com runs outdated Apache 2.4.18 and outdated OpenSSH 7.2 P2. The security of the whole server setup isn't very exemplary. Furthermore, the TLS configuration supports insecure RC4 for encryption and weak cipher suites.

See also my comparison in #454

Discussion can continue in #454

Was this page helpful?
0 / 5 - 0 ratings

Related issues

BurungHantu1605 picture BurungHantu1605  ยท  46Comments

ph00lt0 picture ph00lt0  ยท  30Comments

ghost picture ghost  ยท  37Comments

Thorin-Oakenpants picture Thorin-Oakenpants  ยท  41Comments

ghost picture ghost  ยท  40Comments