3 ms·
This isn't about keeping the content private for the users. This is all about removing the server's ability to read the content, to attempt to absolve the serve
by phpnode 14y ago
This isn't about keeping the content private for the users. This is all about removing the server's ability to read the content, to attempt to absolve the server owner of liability for that content. Therefore the server has no incentive to lie about the encryption algorithm used.
- mike-cardwell 14y agoThis is how HushMail works for email. Except they can be (and have been) compelled to send backdoored code to individual end-users in order to access their users keys and hand over the unencrypted data to their government.
- riffraff 14y agobut this does not guarantee that the server won't read that more than stating "I will not read your data".
- phpnode 14y agothe server doesn't want to read the content! Otherwise they would just store it in the clear. If the server can read the content then they are liable if that content infringes copyright. The theory is that if the server cannot read it, they're not liable. I would not like to be the first one to test this strategy out in court however