4 ms·
There is a way to get around #3 although inefficient. Everytime information is posted by your users you can create 2 copies of encrypted information. One with u
by coo1k 10y ago
There is a way to get around #3 although inefficient. Everytime information is posted by your users you can create 2 copies of encrypted information. One with users password for them to view. The other would be using your key, but you cant simply use password for encrypting your copy, that would be insecure since you need to store your password on server. Instead you can use asymmetric encryption such that you can use your public key to encrypt the information. Then you can use your private key to login to you website and view all information.
- tixocloud 10y agoBasically my database will always be 2X? Curious but given that WhatApp recently encrypts messaging end-to-end, does this mean that even they can't view the information? Does this mean WhatsApp would have no way of detecting if it's application is being used for organizing illegal activity?
- coo1k 10y agoYes. See para 2. https://blog.whatsapp.com/10000618/end-to-end-encryption https://blog.whatsapp.com/10000618/end-to-end-encryption
- coo1k 10y agoOR you could encrypt user password with your public key. Then when you login, you can decrypt user password with your private key. Then go on decrypting user information with that password. This way you won't have to make copy of information posted by users and still will be able to view it with admin login.
- zimpenfish 10y agoDoesn't that mean anyone who captures the "admin" private key has full access to the database?
- coo1k 10y agoYes, but since the key resides with admin and not on server, I am assuming the private key will be stored securely.