4 ms·
Seems like if you really cared for the contents of a textarea, for instance, you could tokenize the text client side and encrypt each token with the client side
by methehack 13y ago
Seems like if you really cared for the contents of a textarea, for instance, you could tokenize the text client side and encrypt each token with the client side private key then you could similarly encrypt the search tokens client side and search serverside not knowing what you were searching for.
However, I take your point. Lots of work, not quite the same. It still seems like the facility should be baked in though so that application's could make the proper tradeoffs.
- arjunnarayan 13y agoSeems super vulnerable to frequency analysis though. However, if this is a path you might want to go down, you might want to look at CryptDB, a research project that looks at keeping a server side encrypted database and allows for queries in a principled way: http://css.csail.mit.edu/cryptdb/ http://css.csail.mit.edu/cryptdb/
- michaelt 13y agoProducts like CipherCloud reportedly work like you suggest. Unfortunately it's not very secure. If you split the text into words, discard case and encrypt each word, the NSA can just e-mail you a dictionary file, match the line numbers in the dictionary file ciphertext to line numbers in the dictionary file plaintext, and they've got your secret decoder ring (at least for every word in the dictionary file).