INPLAIN.SITE
INTERFACE 2.4 // CRYPTO CONSOLE
MODE ENCODELINK LOCALCLK 10:53:28
REFERENCE

HOW IT WORKS

INPLAIN.SITE · LOCAL ONLY · NO UPLINK

Big picture

inplain.site hides secret messages inside pictures. It does two things at once:

  1. Locks your message with strong encryption so nobody can read it without your password.
  2. Hides that encrypted data inside tiny colour details of a PNG image so the picture still looks normal. If you upload JPEG, non-animated GIF, or WebP, the app flattens and converts it to PNG internally; the download is always PNG.

Everything happens in your browser. No images or messages are sent to a server.

Step 1: Turn your message into secret code

You type a message and choose a password. The app turns your text into numbers, mixes your password with random data, and runs a slow maths function to get a strong secret key. It then uses AES-GCM encryption to scramble your message into ciphertext that looks like random noise.

AES-GCM also adds a built-in check so that if anything is changed, decryption fails instead of giving you broken text.

Step 2: Pack everything together

The app builds a small container that holds:

  • A label that says "this came from inplain.site".
  • A version number.
  • The random salt (for key derivation).
  • The random IV (for AES-GCM).
  • The length of the ciphertext.
  • The ciphertext itself.

All of this is combined into one sequence of bytes, ready to hide in the image.

Step 3: Hide the data in pixel colours

Digital pictures are made of pixels. Each pixel has red, green and blue values, each from 0 to 255. The last few bits of those values don't affect how the colour looks to your eyes.

inplain.site takes advantage of this. It changes just the last 1-3 bits of the red, green and blue channels in each pixel to store bits of your encrypted data. To you, the picture still looks the same; to the computer, those tiny changes hold your secret.

Step 4: Getting the message back

To read a hidden message, you:

  1. Upload the stego image.
  2. Enter the password.
  3. Click decode.

The app reads the same tiny bits from the pixels, rebuilds the container, recreates the secret key from your password and the salt, and uses AES-GCM to decrypt the ciphertext. If the password is wrong or the image is damaged, the decryption fails. If it works, you see your original text.

Why PNG and not JPEG?

PNG is lossless, which means every pixel value is preserved exactly. JPEG is lossy: it throws away detail to save space and completely scrambles the tiny bit-level changes we use for hiding data.

That's why inplain.site embeds into PNG and outputs a PNG: it keeps the hidden bits intact so your message survives. Other input formats are flattened and converted to PNG before embedding.

What this protects you from

  • People who see the image but don't know a message is there.
  • People who suspect a message but don't know the password (they only see random-looking encrypted data).
  • Accidental changes: if the image is corrupted, decryption fails rather than giving you nonsense.

What it doesn't protect against

  • Weak passwords that are easy to guess.
  • Websites that resize or recompress your images (which can destroy hidden data).
  • Specialised experts using tools to detect that steganography has been used at all.

To use it safely, choose a strong password, keep encoded images as PNG, and avoid services that recompress them if secrecy matters.