3 ms·
Thanks for checking it out! Apologies for not striking the right balance of brevity while also being informative for you. I'm trying to improve there. All the
by mrdazm 7y ago
Thanks for checking it out! Apologies for not striking the right balance of brevity while also being informative for you. I'm trying to improve there.
All the sensitive data is encrypted at rest using a key/passphrase determined by the user. Passbox doesn't store it and can't assist if it's lost/forgot.
That key would need to be shared with your trusted users and they would need to create their own Passbox accounts. Only folks you assign to your account (via email) can request access to view your data. No one else.
On the standard plan you can assign as many trusted contacts as you'd like. This is potentially useful for segmenting who gets what collections of data.
Both you and the requested user are notified of access requests to your account and also of any approved requests. A group without assignees is shared with all the trusted users you've linked to your account if they're approved access.
Any trusted user you assign can be easily removed or replaced.
---
Again thanks for your perspective! This is one way I'm thinking about tackling it and appreciate other ideas.
- russfink 7y agoHave you thought about secret sharing cryptographic schemes? Nobody gets access to your data until most everyone that has a share of the key agrees that something bad has happened to you.
- mrdazm 7y agoI have - before this post even. It's been mentioned a few times in this post too. It's something to think about but not a current priority. Thanks for the suggestion! Oh, it's called Shamir's Secret Sharing by the way