Archived
0bin vs zerobin #454
Closed
opened 2018-04-29 13:28:12 +00:00 by kewde
·
13 comments
No Branch/Tag Specified
master
dependabot/bundler/nokogiri-1.13.6
dependabot/bundler/addressable-2.8.0
freddy-m-patch-3
pr-add_RemoveMyPhone_sponsor
pr-browser_cleanup_1257_1328_1430
freddy-m-patch-2
freddy-m-patch-1
pr-vpn_hated_one_video
cdn
update-nitrohorse-image
promote-metager-to-card
hardware
pr-add_azirevpn
pr-add_mailfence
shop
1673
pr/1658
i18n-simple
sponsorship-edits-nov2019
i18n
ipfs
blacklight447-ptio-patch-3
blog
remove-windows-icons
pr/1147
i18n-testing
add-beautify
No results found.
Labels
Clear labels
:mag:🤖 Search Engines
approved
dependencies
duplicate
feedback wanted
high priority
I2P
iOS
low priority
OS
Self-contained networks
Social media
stale
streaming
todo
Tor
WIP
wontfix
XMPP
[m]
₿ cryptocurrency
ℹ️ help wanted
↔️ file sharing
⚙️ web extensions
✨ enhancement
❌ software removal
💬 discussion
🤖 Android
🐛 bug
💢 conflicting
📝 correction
🆘 critical
📧 email
🔒 file encryption
📁 file storage
🦊 Firefox
💻 hardware
🌐 hosting
🏠 housekeeping
🔐 password managers
🧰 productivity tools
🔎 research required
🌐 Social News Aggregators
🆕 software suggestion
👥 team chat
🔒 VPN
🌐 website issue
🚫 Windows
👁️ browsers
🖊️ digital notebooks
🗄️ DNS
🗨️ instant messaging (im)
🇦🇶 translations
approved, waiting for a PR
Pull requests that update a dependency file
The Invisible Internet Project (I2P)
Operating Systems
A label for stalebot if it gets added
Anything related to media streaming.
Anything covering the Tor network
active work in progress, do not merge or PR (yet)!
Issues or bugs that will not be fixed and/or do not have significant impact on the project.
Extensible Messaging and Presence Protocol
Matrix protocol
Browser Extension related issues
Correction of content on the website
Firefox & forks, about:config etc.
Anything primarily related to site cleanup.
Virtual Private Network
*Technical* issues with the website.
Domain Name System
Anything covering a translated version of the site
No labels
Milestone
No items
No Milestone
No due date set.
Dependencies
No dependencies set.
Reference: privacyguides/privacytools.io#454
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
https://0bin.net/ and https://zerobin.net/
both use the same source code, yet zerobin.net provides an onion domain (http://zerobinqmdqd236y.onion).
Perhaps we should consider swapping them?
Some facts for comparison. Please note that web servers which do not disclose version information can be vulnerable, too. There is no way to check this without server access.
https://0bin.net
https://zerobin.net
https://ghostbin.com
https://privatebin.info
https://hastebin.com
Edit (May 26, 2018): Updated findings.
Edit (May 27, 2018): Added further information and projects mentioned by @kewde and added hastebin.com which is also listed on privacytools.io
@Shifterovich
@infosec-handbook
Please run the same analytics for the following websites, their results will determine the order of the section.
https://ghostbin.com/
https://privatebin.info
I'm currently going to propose a replacement of 0bin with zerobin.net.
Then re-ordering it to: PrivateBin - ZeroBin - Ghostbin (unless your research shows a different picture).
https://github.com/PrivateBin/PrivateBin/wiki/FAQ#should-i-switch-from-zerobin-to-privatebin
@kewde
I added the results to the overview above. I also added hastebin.com which is currently listed on privacytools.io, too.
zerobin.net seems to be the only recommendable service when I look at the results. However, since zerobin.net doesn't disclose version information we can't be 100% sure that they don't use outdated software, too. Furthermore, I didn't look at the implementation of their code for secure pastebins.
In a nutshell:
Create a PR changing the order and adding some information. Regarding Ghostbin, we should warn users that while Ghostbin - the software - is good, ghostbin.com's security is worrisome.
@infosec-handbook
I believe the 10 third-party connections are related to the .info website (privatebin.info)? - which hosts the source code, in particular the 8 unique github badges will cause third party connections.
The actual pastebin website is the .net domain https://privatebin.net/
It's a bit unclear from your comment on which domain these third party connections are present.
Changing the privatebin url on the website to the .net domain.
Also out of curiosity - what tools are you using for the analysis?
It could perhaps be a standard procedure for analyzing websites we recommend.
Found it: https://infosec-handbook.eu/blog/online-assessment-tools/
@kewde
Right. https://privatebin.net/ has 0 connections to third parties and doesn't set cookies.
I use the web services mentioned in the blog article and several well-known tools like nmap, sslyze, sslscan, dig, openssl etc. to analyze web servers.
I think we shouldn't recommend it then. (#408)
hi guys, i've removed zerobin recently because of this message from the dev:
Source: https://sebsauvage.net/wiki/doku.php?id=php:zerobin
Seems like PrivateBin is the only choice at the moment? I've decided to link to our installation, too.
https://www.privacytools.io/providers/paste/
Should we remove Ghostbin? Replace it with something or just leave PrivateBin as the only choice?
Ghostbin now displays a message that it will be shutting down this month.
I guess PrivateBin is the only choice. Is there a way to integrate it with ShareX?
Ghostbin removed via #931
as we now list privatebin, this issue seems outdated, closing.