3 ms·
1) What happens when you get breached? Is there some kind of e2ee-guarantee where the user holds a specific encryption key that they can reveal once, so that yo
by ev1 4y ago
1) What happens when you get breached? Is there some kind of e2ee-guarantee where the user holds a specific encryption key that they can reveal once, so that you can never reveal any data to any site or person without the user consenting at that exact moment in time once?
2) This means that the underlying app can pressure you to reveal the person, removing "guaranteed anonymity" (ex: crime tip, revealing equals death)
3) How absurdly does this affect any kind of conversion rate?
- JordanRavka 4y agoGreat questions. We go out of our way NOT to collect data. Our job is to prove you are real and nothing more. However, we never want this idea to be used to hurt someone so the architecture is designed to be vulnerable to a warrant signed by a judge in a democratic nation and invulnerable to everything else. Essentially, that means with our consent (ie, we accept the warrant) and the consent of one of parties of the transactions, we can reveal a relationship exist, but nothing more. Our goal is to add trust & privacy to all the normal stuff that people do every day. Our current thinking is that no one would agree to have their phone verified and Face AI recorded, even anonymously, if they are up to something naughty.
- JordanRavka 4y agoI should also mention that the overall goal is to have all the user's data stored on their individual phones with a private key that even we don't have access to. For right now, that's overkill. But soon I am hoping that I can state any data-breaches are meaningless. Every record is encrypted with a different key that is inaccessible. I believe "Anonymous but Verified" can solve so many problems. We can be a single source of "truth" for allowing both trust & privacy. We don't provide an identity, we provide proof an identity exists. ev1, I would love to pick your brain. If you have a moment, please reach-out to jordanravka@trustme-its.me (with any luck, a few years from now I will never have to post my actual email again :)