4 ms·
> You can't have both. If the service has account recovery after you lose your password or encryption keys, it can only mean that there is no any meaningful enc
by thecodrr 5y ago
> You can't have both. If the service has account recovery after you lose your password or encryption keys, it can only mean that there is no any meaningful encryption.
Incorrect. Check Notesnook[1]. It solves both of those things.
[1]https://notesnook.com/ https://notesnook.com/
- actinium226 5y agoHow do they achieve it?
- thecodrr 5y agoCheck this comment: https://news.ycombinator.com/item?id=26845877 https://news.ycombinator.com/item?id=26845877
- Andrew_nenakhov 5y agoIt is obvious that you misunderstand something. Please respond with how exactly they achieve this.
- thecodrr 5y agoIt's very simple. Since the encryption key is basically derived from your password, Notesnook allows you to backup the encryption key. This encryption key + a random salt is used to encrypt all the data client-side. In case you forget your password but have the encryption key somewhere safe, you can easily use the encryption key to have your data decrypted. Notesnook does the above by sending a recovery link to your email. After you click on the email, it authenticates you for a short period of time (30m) and shows the recovery UI. You can put your recovery key in the input. The app downloads the encrypted data from the server, decrypts using the key you gave, and if successful, asks you for a new password. Once you give the new password, it re-encrypts everything using the new encryption key. All this happens in 2 steps. You can try it out yourself.
- Andrew_nenakhov 5y agoIf you have the encrypted key 'somewhere safe', it is not account recovery because your key was never lost. It is just a more elaborate password change. As I've said, you can't have both meaningful encryption (as in service operators can't decrypt data by themselves) and account recovery (as in you've lost credentials necessary to access account).
- thecodrr 5y ago> If you have the encrypted key 'somewhere safe', it is not account recovery because your key was never lost. It is just a more elaborate password change. Uh...what? I think you misunderstood. You use the "password" to access your account, encryption key to decrypt the data. You lose the password, you lose access to your account and your data. However, server has the ability to grant you access to your account without the password. BUT Access is not equal to decryption of data. The key that you have is used to decrypt your data on your device. The "service operator" is never involved in the decryption step; only the access step. This is the only way to recover account access + data for zero knowledge apps. It is similar to the [backup data -> delete account -> create new account -> restore backup] process but it's automated and much more secure.
- Andrew_nenakhov 5y ago> The key that you have is used to decrypt your data on your device. Oh so you need a safely stored key and your own device to decrypt data. Lol. Why do you say we need to use that service, if all is done on user's device? but being serious, everything you say just proves my point, yet, somehow, you refuse to see it.