3 ms·
The multi-channel verification and tiered escalation are the way to go. that's the hard part on the trigger side. What I keep coming back to with anonymous ser
by frank_be 7mo ago
The multi-channel verification and tiered escalation are the way to go. that's the hard part on the trigger side.
What I keep coming back to with anonymous services is the delivery experience. Once the switch fires, what does the recipient's journey actually look like? Especially if they're non-technical (which, statistically, they probably are).
There's an interesting tension between keeping the service zero-knowledge and making the output usable by someone who's never touched a terminal.
Curious how you're thinking about that side of it.
- alcazar 7mo agoHere we prioritize ease of use. The only way to make a message-sending service truly zero-knowledge is to require contacts to upload a public key beforehand and encrypt every message with that key before storage in the database. Unfortunately, this approach requires contacts to be technical people who understand encryption, keys, and key custody. When you die, you want to reach your family and friends—not only the tech-savvy ones. So we encrypt messages at rest with a key stored separately from the database. This forces attackers to compromise two separate infrastructures (and before we notice and rotate the keys) to access any data. When sending the messages, we decrypt them in memory and deliver them in plaintext. That way, your parents don’t need a computer science degree to read your last message. And if your threat model requires it, you can also use our Portable Secret to password-protect the documents. We provide both options.
- frank_be 7mo agoSmart trade-off. The "two separate infrastructures" model is pragmatic — perfect security that nobody can use is no security at all. The Portable Secret option is a nice touch for the paranoid-but-organized crowd. Do you find most users actually use it, or does the convenience of plaintext delivery win out?
- alcazar 7mo agoMost users stick to plaintext. That's expected. Under typical threat models, convenience & ease of use outweigh perfect security.