# Remove the statement about Send's official instance

**URL:** https://discuss.privacyguides.net/t/remove-the-statement-about-sends-official-instance/27564
**Category:** Site Development
**Tags:** rejected
**Created:** 2025-05-14T03:06:57Z
**Posts:** 14

## Post 1 by @anonymous261 — 2025-05-14T03:06:57Z

Send’s official instance will be terminated by May 24.

Could Privacy Guides plan on [hosting](https://discuss.privacyguides.net/t/services-hosted-by-privacy-guides/27357) an instance?

> **[Send](https://send.vis.ee/)**
>
> Encrypt and send files with a link that automatically expires to ensure your important documents don’t stay online forever.

---

## Post 2 by @KevPham — 2025-05-14T15:35:20Z

This seems like an easy of enough change. All in favor for it personally

---

## Post 3 by @jonah — 2025-05-14T15:37:12Z

> Costs are getting too high to keep hosting this service.

I wonder what their costs actually are?

---

## Post 4 by @Weewaawoo — 2025-05-15T02:31:54Z

Maybe a link to the [official list of public instances](https://github.com/timvisee/send-instances/tree/master?tab=readme-ov-file#instances) instead?

Edit: scratch this idea. There dev notes that there is no way to verify the instances for security/privacy. The best option is for another trusted group to fill the void or of course self hosting.

---

## Post 5 by @jonah — 2025-05-15T02:58:00Z

I think ultimately all of these instances will fall to [the original reason](https://blog.mozilla.org/en/uncategorized/update-on-firefox-send-and-firefox-notes/) Firefox Send was discontinued:

> Unfortunately, some abusive users were beginning to use Send to ship malware and conduct spear phishing attacks. This summer we took Firefox Send offline to address this challenge.

---

## Post 6 by @redoomed1 — 2025-05-15T03:54:51Z

> <https://github.com/privacyguides/privacyguides.org/pull/3042>
>
> List of changes proposed in this PR:
> 
> (I'll mark as ready for review on or a l…ittle before <del>May 24</del> June 7. Read below for why.)
> 
> - Send
> - Remove mentions of Send's official instance as it will be terminated by <del>May 24</del> June 7
> - Relevant discussion: https://discuss.privacyguides.net/t/remove-the-statement-about-sends-official-instance/27564
> - Link to the project's repository instead of the defunct official instance for the card's primary button
> - Document Collaboration page
> - Mention CryptPad's official public instance and add button that links to list of public instances
> - Frontends page
> - Move the admonition about Old Reddit from under the Redlib card to under the "Reddit" header since it's not directly related to Redlib
> - General Changes
> - Move lines about public instances and more technical information to the description under recommendation cards based on [this feedback](https://github.com/privacyguides/privacyguides.org/pull/3032#discussion_r2087450680) and to keep card descriptions succinct
> - Spell out abbreviations like "E2EE" for the first instance of the term on the page, then use the abbreviation for the subsequent instances
> - For "Repository" buttons, embed direct links to project's Readme to differentiate them from "Source Code" links

---

## Post 7 by @Niek-de-Wilde — 2025-05-15T07:07:40Z

This is why we cannot have nice things.

---

## Post 8 by @jonah — 2025-05-15T13:21:23Z

> [@Weewaawoo](#):
>
> There dev notes that there is no way to verify the instances for security/privacy.

We need to look into whether using the ffsend CLI tool eliminates the need to trust the instance, because if that tool performs the encryption before upload the risk is very reduced.

---

## Post 9 by @any1 — 2025-05-16T07:15:25Z

> `ffsend` uses client side encryption, to ensure your files are securely encrypted before they are uploaded to the remote host. This makes it impossible for third parties to decrypt your file without having the secret (encryption key). The file and its metadata are encrypted using `128-bit AES-GCM` , and a `HMAC SHA-256` signing key is used for request authentication. This is consistent with the encryption documentation provided by the [Send](https://github.com/timvisee/send) service, `ffsend` is a tool for.

Taken from [here](https://github.com/timvisee/ffsend#client-side-encryption).

---

## Post 10 by @Weewaawoo — 2025-05-17T15:42:14Z

But anyone with the url can decrypt the file which would mean the server stores the private key. This wouldn’t be e2ee and would still require trust of the server. As far as the “optional” password it sounds like this happens outside of the encryption. Does it wrap it in another layer of encryption or just an another wall?

---

## Post 11 by @any1 — 2025-05-23T18:23:41Z

Sorry for the late reply. If one only uses the command line ffsend tool without visiting the hosted instance, the instance never gets the encryption secret, which is stored behind the hash of the URL that can be shared. Using the hosted instance with the website instead of the ffsend command line tool is prone to interception of the encryption secret if the instance has modified the website’s source to steal it. Using only the ffsend command line tool is safe regardless of the instance used because even a malicious instance never gets the encryption key.

TL;DR: ffsend command line tool is safe regardless if instance is malicious.

[Source](https://github.com/timvisee/ffsend?tab=readme-ov-file#note-on-share-link-security)

---

## Post 12 by @Weewaawoo — 2025-05-23T21:38:48Z

This is excellent news. Thanks for explaining.

---

## Post 13 by @redoomed1 — 2025-05-28T01:47:24Z

> [@anonymous261](#):
>
> terminated by May 24

The official instance now shows a termination date of June 7th.

Following the information provided by @any1, I think we can do more than just remove the statement about Send’s official instance:

> [@FFSend (Command Line File Sharing Application)](https://discuss.privacyguides.net/t/ffsend-command-line-file-sharing-application/27889):
>
> Website [https://github.com/timvisee/ffsend](https://github.com/timvisee/ffsend)Short description This is a version of Send (currently listed on the File Sharing and Sync page) used through a command line. The developer also notes a [difference in security](https://github.com/timvisee/ffsend?tab=readme-ov-file#security) between Send’s web-based version and command line version: It would be possible however for a webpage to load some malicious JavaScript snippet that eventually steals the secret from the link once the page is loaded. Although this scenario is extremely unlikely, there are some …

---

## Post 14 by @redoomed1 — 2025-06-21T14:33:37Z

An [update](https://github.com/timvisee/send-instances/issues/90#issuecomment-2983518588) on this:

> At least for the next year, we were able to save Tim’s instance through a generous sponsorship from Thunderbird.

The banner on the official instance about its imminent termination has also been removed.

---

## Post 15 by @redoomed1 — 2025-06-21T14:37:45Z


