All releases

Version 0.88.1

2026-08-22 09:57:59 UTC

HotfixBeta

Security

1
  • While an account code is on the screen, the human-check script is not in that page.

    The human check is served by Cloudflare, and its script runs inside the NMTS page rather than in a frame of its own — so it can read anything that page is showing. The script is fetched when you press the button and the code was still displayed while the request was in flight, so the moment it arrived was the moment an account code was on screen. Your account code is the one value here that cannot be reissued, so creating an account, signing in and erasing by code now take the code off the screen while they send, and the field keeps what you typed. A script that has arrived stays for as long as that page is open, so closing this completely needs the widget in a frame of its own on a separate address.

NMTS — cloud storage that encrypts in your browser