Integrity Breach in Correspondence. One-Time Note Services.

02 хв

No matter how reliable the method of information transmission you choose, from a security perspective, it is better to use multiple communication channels, breaking its integrity. For example, if you need to transmit a combination of a username and a password, you send the username one way and the password another. In this case, one-time note services can help you.

One of the most popular services is Privnote. Privnote is a service that allows you to create one-time notes that are deleted after being read. Using Privnote is very simple: you create a note, get a link for one-time reading, and send it to your interlocutor.

![](https://book-cyberyozh.ams3.digitaloceanspaces.com/1745366435893-Изображение 281.jpeg)

![](https://book-cyberyozh.ams3.digitaloceanspaces.com/1745366463028-Изображение 282.jpeg)

Although this is an old and reputable service, we will not trust it with all our information; its task is only to break the information chain. Thus, neither Privnote will have complete information, nor will it remain in the correspondence.

Pay attention to the link: it represents the website address/note identifier#client key. The client key is stored in the link as an anchor, or in Russian – якорь. An anchor is the part of the URL that comes after # in the link and is never sent to the server (RFC on URL http://www.faqs.org/rfcs/rfc1808.html, section 2.4.1). The browser does not send this part of the link, and the server does not accept it, so the client key does not leave the client's computer without their consent. The owners of Privnote theoretically cannot decrypt your note.

Let me give you an example of practical use of the Privnote service. You have the task of transmitting a person's phone number and information so that no valuable data remains in the correspondence. You send the interlocutor the following: "Tomorrow definitely call https://privnote.com/9qn1wkwq#Kuz62vdzL Ivan". When the interlocutor clicks the link, they see the note.

![](https://book-cyberyozh.ams3.digitaloceanspaces.com/1745366497461-Изображение 283.jpeg)

Another example. You need to transmit confidential data for connecting to a server. For instance, you send the port, IP address, and username in plain text via the Telegram messenger, while you send the password in the form of a Privnote note. You send the following: "111.11.111.111 port 17893 username root password https://privnote.com/9qn1wkwq#Kuz62vdzL".

Корисно?

Будьте в курсі

Підпишіться на наші оновлення, щоб нічого не пропустити.