Ideas worth keeping

Site

Language

Secret Letter

Encrypts a message with the name of whoever is writing it. Only someone who knows who sent it can open it.

Everything happens in the browser. The text is encrypted with AES-256-GCM and the key is derived from the name with PBKDF2, at 250,000 iterations. Nothing is sent anywhere and nothing is stored. Capitals and extra spaces are ignored; accents are not.

The cipher itself is the ordinary, well tested kind. The weak point is the key: a name is short, often easy to guess, and every letter you send carries the same one. So this is a game, not a safe. I picture it at a summer camp or in a treasure hunt, where working out who wrote the thing is half the fun.