Keeping CipherDrive Share Links Secure

A CipherDriveâ„¢ share link can be security-sensitive because the complete link may provide everything a recipient needs to request and decrypt a shared object.

For sensitive files, do not treat a Public Link like an ordinary public webpage address. Anyone who obtains the complete working link and required key material may be able to access the content while the share remains valid.

Use a trusted delivery channel

Send sensitive links through a channel appropriate for the sensitivity of the file. Consider whether:

Be careful with URL fragments

Some encrypted-sharing designs keep decryption key material in the URL fragment after #. Ordinary browser requests normally do not send that fragment to the web server.

However, the fragment can still be exposed on the client side if the full URL is:

Avoid unnecessary URL shorteners

Do not route a sensitive CipherDrive link through an untrusted URL-shortening or link-analysis service. A third party that receives the complete URL may gain access to sensitive sharing information.

A link posted in a public chat, forum, social network, source repository, issue tracker, or webpage can be copied indefinitely even if you later delete the post.

Remove access when:

Remember that revocation is not remote deletion

Even perfect link hygiene cannot erase a file that someone already downloaded or copied.

Protect the device used to create shares

A compromised browser, malicious extension, or infected device can expose links, local keys, decrypted content, or active sessions.

Keep the device and browser updated, limit extensions, use a strong device lock, and avoid creating sensitive shares from public or shared computers.

Review sharing regularly

Where CipherDrive provides a list of active shares or Public Links, review it periodically and disable anything that no longer serves a purpose.

A Public Link is only as private as the people, devices, and channels that handle the complete link.