Security
FerryKey is built so that our servers, and anyone who breaks into them, can’t read your bookmarks. Here’s how, in brief.
Design summary
- Your keys are made on your device. Setup creates a 256-bit random secret, shown as 24 recovery words (BIP39). Keys are derived from it with HKDF-SHA256. The words never leave your device, and each browser forgets them once it’s set up.
- Each browser has its own key. Every device generates its own Ed25519 signing key and a hybrid post-quantum key pair (ML-KEM-768 + X25519, HPKE) for receiving data keys. The server checks every request’s signature against a hash-chained, signed list of your devices.
- Everything is encrypted end to end. Bookmarks and device names are encrypted with AES-256-GCM. Each message is bound to its account, collection and position, so the server can’t move or replay it unnoticed. Data is padded to 1 KiB blocks to hide exact sizes.
- Lock-out switches keys. Locking out a device removes it from the signed device list, and FerryKey moves to new random keys that the removed device never receives.
- Signed history. Each new version of your data is signed by the device that wrote it and chained to the one before, so the server can’t forge or quietly rewrite your history.
- Nothing to steal. No passwords or email addresses are stored. The server holds public keys, signed logs and ciphertext. Keys are full-strength random values, so a database copy can’t be brute-forced.
- Push notices carry no content. Live-update notices only say “something changed”, and devices verify everything they then download.
- Hosting. AWS, Sydney region (ap-southeast-2), TLS only. The website and extension load no third-party code.
What FerryKey does not protect against
- Someone who gets your 24 words, or uses an unlocked device of yours, can read your bookmarks.
- A locked-out device keeps whatever it had already downloaded.
- The server can see metadata: when your devices sync, how many devices you have, and roughly how much you store.
- The server could refuse to store or deliver your data. It can’t read or forge it.
- You have to trust the extension you install. Only install FerryKey from the official Chrome Web Store and Firefox Add-ons listings linked on this site.
Responsible disclosure
If you believe you’ve found a security problem in FerryKey, please tell us privately first.
- Email support@ferrykey.com with “Security” in the subject, a description, steps to reproduce and the impact you expect.
- We’ll acknowledge your report within 3 business days and keep you updated until it’s fixed.
- Please give us 90 days to fix the problem before you publish. We’re happy to credit you.
- Test only against accounts you created. Don’t access other people’s data, degrade the service (no load testing or spam signups), or use social engineering.
We won’t take legal action against good-faith research that follows these guidelines.