4 ms·
I would say that your questions are valid, but not necessary to tackle in the short term. In fact, if you don't store the encryption key then the problem doesn'
by partisan 7y ago
I would say that your questions are valid, but not necessary to tackle in the short term. In fact, if you don't store the encryption key then the problem doesn't exist at all. It is up to the client library to implement the prescribed encryption algorithm and up to the user to provide the encryption key.
In the end, you are simply storing bits. How those bits are interpreted is up to the client. If a user distrusts a client then they can download, re-encrypt and upload the content.
Btw, I had the same idea for a hosted solution. My concern became that illegal content would be uploaded to my server and I quickly went away from this, but I do think it is an interesting idea.