This implementation is a bad idea to use because of the aforementioned security smell.
Another implementation would have to solve the problem of how to ensure message security while still being able to deliver the message at the right time.
The "right" answer for something like this is as you said, lawyers, but "get you killed" is... overly dramatic. Snowden is, after all, still alive.
If you don't want this to happen, I suggest taking more care to edit flamebait out of your comments. Leading with "Don't be so melodramatic," "That's so unbelievably false it makes me sad that you," "You stop", etc. guarantees poor results and therefore off-topic snippage.
Stop. Broken privacy tools have gotten people tortured and killed. Just because you can't imagine it happening to white dudes in the US and western Europe doesn't mean it isn't the norm pretty much everywhere else.
You were fine before your "Snowden is still alive" thing. I don't have an opinion about whether Stavros's site is a serious privacy application. Maybe it isn't. But other manifestly unqualified people have tried to deliver privacy to people and failed catastrophically.
It is definitely not a serious privacy application. It's meant for sending things like last goodbyes to loved ones, not state secrets. I will make this clearer on the front page, on a second read the "stored securely" part might be misread as "secure against the NSA" rather than "secured against a curious DB admin", thanks for the clarification.
I'd go pretty far in that direction, were I running this service. Something along the lines of "hey, I do my best, but anything that'd significantly impact anyone's life if it were disclosed accidentally or compromised is best stored offline, with information on how to find it being all that's actually set up to go out via my service." And maybe I wouldn't even be comfortable with that.
Actually, on further reflection, I wouldn't be comfortable running a service like this at all, for reasons amply detailed elsewhere in these comments - in short, it's a great way to paint a target on your chest for everybody from random scammers to state-level actors. I must admit I am considerably impressed by your courage in continuing to do so. Don't get me wrong - I think you must be a madman. But I can respect a very brave madman!
I added something here (https://deadmansapphr.appspot.com/help/), hopefully it's clear enough, but let me know if you have any feedback. I would hate to have people thinking this is secure against the NSA or anything.
It's clear as far as it goes, but as I said before, I don't think it goes nearly far enough. It's not just that messages stored with your service aren't secure against state actors - messages stored with your service aren't secure against anyone with the nous to compromise the host(s) on which it runs. And I hope you'll forgive me for saying that, given that you managed to overlook trivial CSRF for a year in the application's request handling code, I'm not entirely sanguine that your host configuration is strongly secure against any, perhaps even most, non-state actors.
That's not something I like saying, and I can't imagine it's all that pleasant to hear, either. I wouldn't say it at all if I did not feel it necessary, and I feel it necessary precisely because there seems to be a severe mismatch here between the gravity of any potential compromise of your service and the measures taken to prevent such a compromise from occurring. You know a lot more about the nature and scope of those measures than I do, of course, and it's possible I'm underestimating them here. I do hope that's the case. If it is, please accept my apologies for having spoken harshly where doing so was unwarranted. If it isn't, I hope you'll attend to that situation as best you can without delay. If you're not sure, then for the sake of your users, I hope you'll bring in someone with the capability to evaluate and resolve whatever security issues exist, and do so with as little delay as possible.
In any case, you've (perhaps accidentally) put yourself in a position that encourages people to invest a great deal of trust in you, and it seems that many people have done so. Had I put myself in such a position, I would not be comfortable remaining in it if I could not be entirely confident I had either done everything within my power to fulfill that trust, or removed myself from that position without betraying the trust I'd found myself ultimately unable to fulfill. But that's just my own evaluation, and perhaps you feel differently.
Sorry. I totally believe you --- but if I were you, I'd take extra care to make it clear that this isn't a security tool, just because of the nature of the secrets you're inviting people to vouchsafe with you.
I'm responding more to the indignant claim that casual security/privacy tools can't harm people. It's true: they are very unlikely to harm the kinds of people who read and write comments like these. Like I said, it was the allusion to Snowden that moved me to comment.
> if I were you, I'd take extra care to make it clear that this isn't a security tool, just because of the nature of the secrets you're inviting people to vouchsafe with you.
Yes, definitely. I need to spend a bit of time clearly communicating "it's fine for telling people you love them, but not that your multinational's CEO defrauded millions of pensions".
That's so unbelievably false it makes me sad that you, a respected member of the security community, are touting it like a clear and present danger to anyone reading this site.
You stop.
Edit: I'm being absolutist because it's easier, rhetorically, but if I have to be explicit, I'm saying that the realistic occurrence of murder as a result of privacy tool usage, one way or another, is low, to understate things. To talk about murder as a problem in cybersecurity is like talking about meteors hitting car windshields.
Are you suggesting it's "unbelievably false" that broken privacy tools have gotten people tortured and killed? A lot of us in the "security community" know this to be true, with specifics.
There's a paid subscription option, and its developer's comments elsewhere in this thread very strongly suggest people are using it in a serious fashion. If you're thinking of it as a toy, your threat model is bogus.
You can, and I think ethically must, take responsibility for the fashion in which people use the tool you make.
If you intend it to be only a toy, then you can, and I think ethically must, make that clear.
If people persist despite all warnings in using it in ways that might cause them harm, then you can, and I think ethically must, cease to make it available.
To do otherwise is dangerously cavalier at best, and incompatible with the minimal degree of responsibility which I would require of an employee or a colleague. Perhaps you feel otherwise. That's your prerogative. But, if so, I do hope, for the sake of any users you might have, that you aren't in a position to make similar decisions yourself.
I'm not talking about 'StavrosK's service here. I'm talking about your evaluation of threat models, which seems to include a great big exception around "well, if people aren't using it the way I want them to, then to hell with them."
Well yeah, actually that's how threat models are built -- you can't protect users from themselves, if a user wants to store all their passwords in a greeting card website, in the little "special message to your loved one" field, there's realistically no way you can stop them.
Your greeting card website's threat model doesn't include this.
Does it? It seems like you'd need to argue that this notional greeting card website made some specific claim of security around the content of that field.
No, I'm done. The author of the tool has come out and explained things to you directly, and if you're going to keep playing games, you can do that with someone else.
Who's playing games? I've read the comments in this thread from 'StavrosK. You and he don't appear to be talking about the same service, and he's the dev. But if you don't feel any purpose would be served by your continued participation, that's your call to make, of course.
I'm not sure, but perhaps the parent poster's idea was that if you have secrets that would be released if you die, you might give people who want to know those secrets an incentive to kill you.
This implementation is a bad idea to use because of the aforementioned security smell.
Another implementation would have to solve the problem of how to ensure message security while still being able to deliver the message at the right time.
The "right" answer for something like this is as you said, lawyers, but "get you killed" is... overly dramatic. Snowden is, after all, still alive.