← All guides

Sharing links and passwords more safely

Most leaked secrets don't leak through clever attacks. They leak because they were pasted into a chat and left there. This guide is about the boring part — the channel you choose — and a routine that takes ten extra seconds.

Last updated: September 2026 · 5 min read

Chat is a permanent record you don't control

When you send a password to someone in a messenger or a work chat, at least three copies exist before they've even read it: your device, the service's servers, and their device. Then multiply by backups, exported histories, and device restores. Deleting the message later removes your copy — not the others.

Work chats add another wrinkle: company platforms are admins of their own space. Depending on the setup and jurisdiction, they may retain or review messages. A WiFi password in family chat is one thing; a production credential in a team channel is another.

Link previews: read before you paste

Most messengers and many mail services fetch every link you send to build a preview card — title, description, sometimes an image. That happens automatically, before the recipient decides anything, and the fetch often comes from a datacenter, not from their phone.

For public pages this is harmless. But it means:

The account-takeover scenario worth knowing: an attacker with access to someone's email or chat can request "password reset" on services and simply read the reset link as it arrives. Any secret that travels through a compromised channel is compromised, no matter how carefully it's phrased. For high-value accounts, split the delivery: even modest separation (code in one channel, password in another, or a time-limited note) beats a single message.

A routine that takes ten extra seconds

  1. Open a burn-after-reading note (we run one at priv.sh0rt.biz). Paste the password or text, pick 1 read for a single recipient, and add a password if the material is sensitive.
  2. Send the note link in the chat — that's fine. It's a link to a locked door, not the key.
  3. Send the note's password separately — a different channel, or at least a different message after the first one has been acknowledged. If either half leaks, it's useless alone.
  4. For files, prefer a note with an upload over a permanent cloud folder. Files in shared drives outlive their purpose, get synced everywhere, and sit in "Shared with me" forever.

The note burns once it's read (or once your read limit runs out). No copy sits in an inbox, and nothing depends on someone remembering to delete the message later.

Honest limits of the approach

None of this is magic, and overselling it would be worse than not writing this guide:

Used with those limits in mind, the routine handles the most common real-world case — the everyday secret sent to a colleague, friend, or family member — far better than a permanent chat message, at a cost of almost nothing.

Have something to send?

Open Burning Notes