Anti brute-force: end session after repeated wrong decrypts
Sender controls time & receive limits
Security Burn™ is a simple rule: if someone repeatedly enters the wrong file password in the same session, the session ends and the connection is torn down.
Why this exists: most “guessing” attacks happen as many attempts in a short window. Ending the session limits live brute-force attempts during an active transfer.
What happens when you hit the limit
After the threshold is reached, the receiver must start a fresh session (re-enter the receive code). The old live session is not reusable.
What it protects (and what it doesn’t)
It helps against repeated online guessing in a live session. It does not replace strong passwords—use 8+ characters and include mixed types when you enable AES.
Best practice
For sensitive files: enable optional AES-256-GCM, compare the passphrase fingerprint emoji on both devices, and set session limits so the link expires quickly.