How Ripenote works
Last updated 26 September 2026
The clock: drand
drand is a public randomness beacon run by an independent group of organizations, in production since 2019. Ripenote uses drand's quicknet network, which publishes a new “round” every 3 seconds. Each round comes with a signature that only the network, working together, can produce.
No single operator holds the whole signing key. It is split into shares using threshold cryptography: a round's signature only appears when a threshold (a majority) of operators combine their shares at that round's time.
The lock: identity-based encryption to a future round
Using the network's public key and a round number, anyone can encrypt a message that can only be decrypted with that round's signature. This is identity-based encryption where the “identity” is a moment in time. When you seal, your device:
- turns your chosen date into a round number (round = ⌊(time − genesis) ÷ 3s⌋ + 1);
- encrypts your letter with a random key using the open
ageformat; - locks that random key to the round with
tlock, drand's open timelock standard; - puts the result in your link, card, keepsake or
.sealfile.
On the date, drand publishes the round's signature. Your browser fetches it from a public drand relay, checks it against the network's pinned public key (a forged key is rejected), and uses it to open the letter.
you (today) drand network (on the date)
─────────── ───────────────────────────
letter ──age──▶ sealed body round R arrives
random key ──tlock(R)──▶ locked key operators combine shares
──▶ signature for R published
link / card / file ◀── you keep browser: verify signature,
unlock key, open letterWhy nobody can open it early — including us
- The signature for your round does not exist until the network produces it. There is nothing to steal early.
- Ripenote never receives your letter. It lives in the part of the link after
#, which browsers do not send to servers. - The unlock time is read from the encrypted data itself, so editing the visible label can't make it open sooner.
- The time the letter was sealed is stored inside the encryption and revealed on opening, so it can't be changed either.
The limits, honestly
- Collusion. If a threshold of drand operators colluded, they could produce future signatures early and open capsules before their date. The design assumes that never happens.
- Not quantum-resistant. The BLS signatures and identity-based encryption used by tlock would not withstand a large quantum computer. drand's own guidance is a long-term security horizon of at least 5 years.
- The network must keep running. If the drand operators shut down and deleted their keys, capsules for dates after that could never be opened. That's why Ripenote shows a risk note for dates more than 5 years away.
- Lost means lost. We can't recover a lost link, card or file, because we never had one.
- Receipts prove when, not who. An X post's timestamp proves when it was posted. It doesn't prove who wrote the prediction, or that other posts weren't deleted.
We never call this “unbreakable”. It's timelock encryption on drand, using the open tlock standard — independently audited, and openable with drand's own tools. Here's how.
Questions that come up
Can you email it on the date? No. We don't store the letter or an address. Send the link now; they still can't open it early. Add a calendar reminder for the day.
I lost the link. We can't recover it. Look in sent mail, messages, the calendar event, the card, or the .seal file.
I forgot the passphrase. Nobody can open it. That's the point of the passphrase.
An emergency — can it open early? No one can, including us.
Inside the X app? Reading works. Open it in your browser to download or print.
Photo locations? Removed on your device before sealing.
Where's the license key? In the purchase email from Dodo Payments. Paste it at /unlock.
The network we use
drand quicknet, chain hash 52db9ba70e0cc0f6eaf7803dd07447a1f5477735fd3f661792ba94600c84e971, scheme bls-unchained-g1-rfc9380, genesis 2023-08-23. The chain info is pinned in Ripenote's code and never taken from a relay.