Security

What Toss protects you from, and what it doesn't. How the pieces fit together is on How it works; what we store is on Privacy.

What Toss protects against

  • Our servers leaking your files. Files never pass through them and are never stored anywhere.
  • The relay reading your file. When a direct path isn't possible, a TURN relay forwards data that is encrypted between the two browsers (DTLS).
  • Our server reading file names. Names, sizes and types are sealed for the recipient's browser before they leave the sender's.
  • A file damaged on the way. Every file is checked with SHA-256 when it arrives and discarded if it doesn't match.

What it doesn't protect against

  • Someone who has your link. Anyone with it can offer you files. Nothing arrives until you accept, and you can make a new link at any time.
  • Seeing each other's IP address. A direct connection between two browsers usually shows it to the other side.
  • What happens after the file is saved. Once it's on the recipient's device, it's up to them and their device.
  • The website itself. Like any web app, Toss runs the code our server sends to your browser, so you trust that code.

The connection code

Our server passes the setup messages between the two browsers, including the recipient's key that the file details are sealed with. A compromised server could try to put itself in the middle of a transfer. It can't do that without swapping keys, and then the two screens show different connection codes. Each side allows at most five tries to agree on a code for a file and then fails the transfer, so a server guessing a matching code has at most about ten chances in a million. The code checks the connection our server set up, not the website's code itself (see above).

So when a file matters, compare the six-digit code with the other person: on a call, in a chat or side by side. The same code on both screens means no one is in between. Different codes mean the transfer can't be trusted: tell us about it. The code appears as the transfer starts, so for a small file it's a check afterwards rather than before.

Report a security problem

To report a vulnerability, email appbits.dev@outlook.dk with a description of the issue and the steps to reproduce it. The same contact is listed in our security.txt.