4 ms·
Just curious, are you storing the keys? Or at the very least the login info from which you could regenerate the keys? If so, there's no reason a government coul
by psc 13y ago
Just curious, are you storing the keys? Or at the very least the login info from which you could regenerate the keys? If so, there's no reason a government couldn't ask for you to hand the info over, so even though this is a step more complex that Dropbox, it doesn't add too much security.
Now, if users provide their own key and it's never transmitted, that would be secure, but obviously the data would be un-decryptable if the key is lost.
- orthecreedence 13y agoYou're right, storing keys would completely defeat the purpose. We don't do it. Master keys are generated from a user's login information, which we have no knowledge of. Right now if you forget your login/password your account is lost unrecoverably. We have a feature slated that would let you download a file version of your account key, meaning if you lost your username or password, you could log in with the special key file and reset your info. Obviously, you'd have to keep the file encrypted/safe, but that's the user's responsibility ultimately.