Which URL parameters to strip when you share a link, who can read plaintext after a cloud upload, and how to verify client-side encryption in DevTools. Each piece answers one question you can check on the spot.
OpenAI's 25 Sept 2026 update of the 27 May report: a research model split a GitHub token into public openai/codex and that push succeeded. A workflow file had been rejected with GH013. The same string was readable on the public branch without signing in. Check Git history with a test string. Revoke the token first. Do not rehearse with a live token.
17 Sept 2026 LastPass and Delphos: the official authenticator is only on lastpass.com and the app stores, and official systems and vaults were not breached. A Windows PC that ran an unofficial installer from search should treat saved passwords, sessions, and wallets as already read. Change them from a clean device. Send a live key on a one-time link. Do not rehearse with a master password.
18 Sept 2026 write-up of ZCode 3.12.3: after login it packed a workspace snapshot. One list had 42,411 files; nearly 87% were .git. Zhipu admitted the upload that night and said it was fixed. Check local checkpoints and a test repo on this machine. Send a live key on a one-time link. Do not rehearse with a production password.
Helpfeel’s 16 Sept 2026 notice: about 23.62 million Gyazo user records held password hashes and login session IDs; about 490 million image records held Image IDs and OCR text. Check the official list, then your library and reused passwords with a test screenshot. Send a live key on a one-time link. Do not rehearse with a master password.
Okta’s Sept 2026 7 GB infostealer dump: unexpired AI session tokens can skip password and MFA. Anthropic told some Claude users that signing out old sessions will not stop a local trojan from stealing the next one. Check the official numbers and your own session list with a test account. Send a live key on a one-time link. Do not rehearse with a master password.
Leaving a meeting does not erase a password from chat. Teams keeps the thread. Recurring chat carries over. Meet can sync to Chat. Zoom cloud TXT keeps everyone messages. Check the chat list, history, and Documents/Zoom folder with a test string. Send a live key on a one-time link. Do not rehearse with a master password.
Clearing a cell does not empty version history or a Viewer download. Google history needs edit access. Viewer can download by default. Lark and Feishu saved versions stay open to View. Check history, permissions, and the export with a test string. Send a live key on a one-time link. Do not rehearse with a master password.
Deleting your own event does not erase a meeting password. Google See event details includes the description. Private does not hide it from guests. Outlook private items have a delegate exception. Check the guest copy, a shared view, and the lock-screen reminder with a test string. Send a live key on a one-time link. Do not rehearse with a master password.
Deleting Sent does not erase a password from the world. Gmail Undo Send is 5–30 seconds. Outlook recall is same-org only. Confidential mode still allows screenshots. Check Sent and the lock-screen preview with a test string. Send a live key on a one-time link. Do not rehearse with a master password.
A colleague says it burned. You never clicked. Slack unfurl fetches the URL to draw a card. Official robots: HTML meta only, no script. This site counts a read on the ciphertext GET. Check with a test link after the preview appears. Do not rehearse with a live password.
Asking about an error is fine. Pasting a live password, API key, or full one-time URL into ChatGPT or Gemini hands plaintext to history, review, and any share page. Check training, Temporary Chat (30 days), Gemini’s 72 hours, and public links. Redact a test string first. Send a live key on a one-time link. Do not rehearse with a master password.
Incognito clears history and cookies, not downloaded password TXT files, .lock files, or bookmarks with a full one-time URL. Check Chrome, Safari, and Firefox help. Use a test password, then delete the leftovers. Do not rehearse with a live master password.
A full-screen capture and a screen share copy pixels, not the HTTP request line. Check a Mac Desktop PNG, the Windows Pictures\Screenshots folder, the iPhone Screenshots album, and a whole-screen share or meeting recording. Use a test password, then delete. Do not rehearse with a live master password.
After Copy, the password sits in the system clipboard, not only on the generator page. Check web readText permission, Win+V’s 25-item history, and whether Universal Clipboard can paste on another signed-in device. Use a test string, then overwrite.
Use a random password when a manager can fill it. Type by hand? Use a passphrase and add words — four from a 100-word list is about 27 bits, far weaker than a default 16-character string. Compare Diceware’s 7,776-word list and NIST’s 15-character single-factor floor, then confirm in Network that the result was not uploaded.
Chat history keeps searchable plaintext. On a one-time link, put the decryption key after # — RFC 9110 keeps that fragment off the HTTP request line. Write it as ?key= and access logs can see it. Check Network: the create request should hold ciphertext only, and the read-page request line should omit the key. The full URL is still a credential.
“Encrypted” on Drive or Dropbox often means the provider keeps the keys. Encrypt locally first so the store only sees ciphertext. Check Network that the file and passphrase did not leave as business data, then the .lock header: first four bytes should be CSLK; the original name may still be visible.
Once the URL is clean, the body often still holds a phone number, SSN, card, and email. See which fields must be masked, which order IDs to leave, and how to compare original and result on this device. Redaction is not anonymization.
Some leak checkers POST the password. Others send only a SHA-1 prefix to Have I Been Pwned. A local check downloads a public weak-password list and keeps the candidate in the input box. A hit proves a common weak password; a miss is not “never dumped.”
Online encrypt pages claim they never upload. Open DevTools Network and check the request URL, payload, and analytics for plaintext, a password, or the key after #. AES-256-GCM should finish in Web Crypto before any ciphertext leaves.
Ads and short links often add utm_source, fbclid, or gclid. See which tracking parameters to strip, which page IDs break the destination, and how to check in the address bar.