About PrivateBin
PrivateBin is a minimalist, open source online pastebin in which the server has zero knowledge of the stored data. Text is encrypted in the web browser using 256-bit AES in Galois/Counter Mode (GCM) before it is uploaded, and decrypted in the reader's browser. The decryption key travels in the URL fragment, so the server never sees it.
It is a fork of ZeroBin, originally written by Sébastien Sauvage, and has been refactored to make it easier to extend. The code is written in PHP and JavaScript and is released under the zlib/libpng licence. The current release when checked was version 2.0.6.
Because PrivateBin is software, there is no single official paste site. Anyone can install it on their own server, and the project publishes an instance directory listing public installations along with their version, whether HTTPS is supported and enforced, a Mozilla Observatory rating, whether file uploads are enabled, uptime and hosting country.
How to create a paste
- Choose an instance from the PrivateBin directory, or install PrivateBin on your own server.
- Type or paste your text. Optionally choose a format (plain text, source code or Markdown), an expiry time, burn after reading, a password or open discussion.
- Select Send. Share the full link, including everything after the
#, as that part holds the key.
Things to know
- Encryption: everything is encrypted client side. If you lose the full link, the paste cannot be recovered, and the instance operator cannot read it either.
- Optional password: adding a password means a reader needs both the link and the password.
- Burn after reading: the paste is deleted after it is first opened.
- Discussions: pastes can allow comments, posted anonymously or with a nickname.
- Per-instance settings: expiry choices, size limits, file uploads and rules are set in each instance's configuration, so they vary between servers.
- HTTPS: the project says installations should only be used over HTTPS, secured with HSTS.
Frequently asked questions
Can the PrivateBin server read my paste?
No. The text is encrypted and decrypted in your browser using 256-bit AES in Galois/Counter Mode, and the key is kept in the part of the link after the # sign, which browsers do not send to the server. The server only stores encrypted data.
Is there an official PrivateBin website to paste on?
PrivateBin is software rather than a single service. The project maintains an instance directory at privatebin.info/directory listing public servers, with their version, HTTPS set-up, security rating, uptime and country.
Is PrivateBin free?
Yes. The software is open source under the zlib/libpng licence and can be self-hosted. Public instances are run independently by third parties, each with its own settings and rules.