FAQ

Frequently asked questions

What is SharePass, and how does it work?

SharePass is a secure data sharing platform designed to protect your confidential information while enabling easy and convenient sharing. It works by encrypting your data using advanced encryption algorithms (AES 256 GCM), creating unique SharePass links that you can send to recipients through various communication channels. When a recipient clicks the link, they can securely access the shared information without the need for SharePass registration.

Why should I use SharePass?

When you share confidential information over traditional channels such as notes, SMS, chatting tools, or emails, you leave a digital footprint. Unknowingly, this footprint remains available in clear text, allowing it to be discovered by hackers and other users.

When using SharePass, you can securely share the required information by encrypting it and sending the link to the recipient. Once the recipient has opened the link, it becomes inactive, leaving no traces of your confidential data.

How do I create a SharePass account?

You can create a SharePass account using one of two methods:

Method 1: Standard account creation

  1. Visit the SharePass Website: Start by visiting the official SharePass website.
  2. Register: Click on the “Sign Up” button, located at the top-right corner of the webpage.
  3. Provide Information: Fill out the registration form with the required information. This includes your name, email address and a secure password. You will need to verify your email account.
  4. Optional Multi-Factor Authentication (MFA): For enhanced security, you can enable multi-factor authentication (MFA) during or after the registration process. MFA adds an extra layer of protection to your account.

Method 2: Social sign-on

SharePass also offers the convenience of social sign-on, which allows you to use your existing Google, WWPass, or Apple account to create a SharePass account. Here’s how:

  1. Visit the SharePass Website: Start by visiting the official SharePass website.
  2. Select Social Sign-On: Look for the option to sign up or log in using your preferred social platform (Google, WWPass, or Apple).
  3. Authenticate: Click on your chosen social platform’s icon and follow the authentication prompts. You’ll need to log in to your social account or confirm your identity.
  4. SharePass Account Creation: Once authenticated, SharePass will create an account linked to your chosen social platform.

These two methods provide flexibility when creating a SharePass account, allowing you to choose the approach that suits you best. Whether you opt for the standard account creation process or the convenience of social sign-on, you’ll be on your way to securely sharing secrets and sensitive information with SharePass.

How do I reset my SharePass account password?

Here’s how to reset the password for both standard email accounts and those using social sign-on with SharePass:

For standard email accounts

If you have a SharePass account linked to your standard email address (not using social sign-on), follow these steps to reset your password:

  1. Visit the SharePass Login Page: Go to the SharePass login page on your web browser or mobile app.
  2. Click on ‘Forgot Password?’ You will be redirected to the password reset page.
  3. Enter Your Email Address: On the password reset page, enter the email address associated with your SharePass account.
  4. Receive a Password Reset Link: You will receive an email containing a password reset link. Click on this link to proceed with resetting your password.
  5. Create a New Password: Follow the on-screen instructions to create a new, secure password for your SharePass account.
  6. Log In with Your New Password: Once you’ve successfully reset your password, return to the SharePass login page and log in using your email address and the newly created password.

For social sign-on accounts

If you have a SharePass account linked to your social media or third-party account, such as Google or Apple, resetting your SharePass password is not applicable. Instead, you will manage your SharePass account through your social media account’s security settings.

To recover or reset your SharePass account password in this case, you should follow the password recovery or reset process for the social media or third-party account that you use to sign in to SharePass. Each social media platform, like Google or Apple, has its own password recovery methods and settings.

If you face any issues during this process, you should refer to the support and assistance resources provided by the specific social media platform or third-party service you use to sign in to SharePass.

Can SharePass read my secrets?

No, SharePass cannot read your secrets. SharePass is designed with a zero-knowledge architecture, meaning that it has no access to the content of the secrets you create or share. Here’s how this works:

  • Client-Side Encryption: When you create a SharePass secret, the encryption process takes place entirely on your device (client-side). SharePass generates a symmetric encryption key, which is used to encrypt your secret data. This key never gets transmitted to SharePass.
  • Encrypted Transmission: Only the encrypted data is sent to SharePass’s servers for storage and sharing. SharePass has no knowledge of the encryption key or the content of your secret. The data is transmitted securely using AES 256 GCM encryption protocol.
  • Decryption on the Recipient’s Device: When someone with the appropriate permissions accesses the secret, the encrypted data is retrieved from SharePass. Decryption occurs on the recipient’s device using the encryption key provided through the SharePass link. Once again, SharePass never has access to this key.
  • Zero-Knowledge Principle: SharePass follows the zero-knowledge principle, ensuring that your secrets remain private and confidential. SharePass, as a service provider, does not have the ability to read or access the content of your secrets, and the encryption keys are kept solely in the hands of the sender and authorized recipients.

In summary, SharePass is committed to maintaining the privacy and security of your secrets. It employs strong encryption practices and a zero-knowledge architecture to ensure that your sensitive information remains completely inaccessible to anyone other than you and authorized recipients. Your secrets are always kept private and secure when using SharePass.

What if the SharePass link goes into the wrong hands?

If a SharePass link falls into the wrong hands, it’s important to understand that SharePass employs several security measures to protect the confidentiality and integrity of your shared secrets. Here are some key points to consider:

  1. PIN Protection: Depending on your settings, your secrets may be further protected by a PIN, or security key. Without this additional authentication, unauthorized users won’t be able to access the secret, even if they have the link.
  2. Expiry and Access Control: SharePass allows you to set expiration dates for your secrets and control who can access them. If the link falls into the wrong hands after it expires or is revoked, it becomes useless.
  3. IP Restrictions: You can configure SharePass to allow access only from specific IP addresses. This adds an extra layer of security, ensuring that only authorized devices can access the secret.
  4. Security Keys: If you’ve enabled security keys, they act as a second factor of authentication. Even if someone has the link, they will still need the physical security key to access the secret.

To further minimize the risk of SharePass links falling into the wrong hands:

  • Always use strong PINs to protect your secrets.
  • Be cautious about whom you share links with, especially if they contain highly sensitive information.
  • Regularly review your SharePass activity and revoke access to any secrets that you no longer wish to share.
  • Keep your security keys secure and do not share them with others.

While SharePass takes robust security measures to safeguard your secrets, it’s essential to use it responsibly and apply additional security layers as needed for the level of confidentiality required.

What is the difference between an “erased” secret and a “deleted” secret?

In SharePass, an “erased” secret means that the main secret content in the database is deleted, but associated attributes like creation time, security settings, access logs, etc., are retained. On the other hand, when a secret is “deleted,” the entire record in the database, including all its attributes, is permanently eliminated.

Can I share secrets with recipients who don’t have a SharePass account?

Yes, SharePass allows you to share secrets with recipients who may not have a SharePass account. They can access the shared content using the provided link and any necessary authentication methods.

Is SharePass 100% effective when transmitting confidential data to a recipient?

SharePass takes extensive security measures to protect your confidential data. However, no system can guarantee 100% effectiveness due to factors beyond its control, such as the recipient’s environment. SharePass ensures strong encryption and access controls, but the security of data in transit and at the recipient’s end also depends on the recipient’s compliance with security practices and the security of their device. While SharePass provides a highly secure platform, users should exercise caution and ensure their recipients follow secure practices to maximize the protection of confidential data.