TimePad is an experimental research implementation. There is no independent
security audit, guaranteed response time, or long-term support commitment.
Security reports should target the current C implementation on main; the
retired Python scripts and historical revisions receive no fixes.
If GitHub's Report a vulnerability option is available, use the repository's private reporting form. Availability depends on the maintainer enabling private vulnerability reporting. If unavailable, open a minimal issue asking the maintainer for a private reporting channel, without publishing the vulnerability or exploit details.
In a private report, include the affected commit, operating system, compiler and libsodium versions, a minimal reproduction using synthetic data, observed impact, and any proposed fix. Do not include real keys, pads, passwords, private messages, or files containing other people's information.
encode/decodeuse XChaCha20-Poly1305 authenticated encryption with a random 256-bit key and a freshly generated 192-bit nonce for each encryption.- A repeated key/nonce pair is unsafe. Random nonces make accidental repetition negligible under correct random-generator operation; uniqueness is not tracked.
- Keys are raw binary files protected by Unix permissions, not password-encrypted files or OS-keychain entries. Protect copies, transfers, and backups separately.
otp-*commands have no authentication. Never reuse a pad to encrypt another message, and do not treat valid decoded bytes as proof of authenticity.- The application cannot protect a compromised account or operating system. It does not hide message lengths or provide key exchange, replay protection, secure disk erasure, or guaranteed protection against swap and snapshots.
- Original plaintext files remain on disk after encryption. Decryption creates another plaintext file. Temporary files can remain after abrupt termination.
See how it works, the case study, and the responsibility and liability notice for the full scope.