5 ms·
I've been thinking of a similar system with e2e sharing of content and I'd love to pick your brain on this if you don't mind :) - What made you go with libsodi
by beingflo 5y ago
I've been thinking of a similar system with e2e sharing of content and I'd love to pick your brain on this if you don't mind :)
- What made you go with libsodium over using the browsers Web Crypto API?
- If you stop sharing an album with someone, do you somehow re-encrypt the collection key or is the recipient still in possession of all the necessary keys to decrypt the data if they get their hands on it?
- vishnumohandas 5y ago- Mature libsodium clients were available across the platforms we were targeting. The APIs seemed well documented and turned out to be a delight to consume. - There are access control checks in place to revoke access to files from removed album participants. But from a cryptographic standpoint, once your keys have been shared (/compromised), the respective files should be re-encrypted.
- beingflo 5y agoThanks for answering! Regarding the second point, does the application do this automatically or is the user expected to re-encrypt data manually?
- vishnumohandas 5y agoWe don't handle this case right now, have added this to our roadmap[1]. I feel that for our use case of storing and sharing personal photos, this might be an over kill. But I'll let the customers decide. There might be usecases I might not have thought of. [1]: https://roadmap.ente.io/option-to-download-re-encrypt-and-re-upload-an-unshared-album-p-2652/ https://roadmap.ente.io/option-to-download-re-encrypt-and-re...
- beingflo 5y agoThat's exactly the problem I'm facing. Especially if there are multiple shares to the same data it gets tricky. Love to see public roadmaps in products btw.!
- vishnumohandas 5y agoYou could perhaps take a look at Skiff's white paper[1] and see how they solve for this. [1]: https://www.skiff.org/security https://www.skiff.org/security