Encrypt messages at rest

(#967) Feature Declined privacy security

Thread

Comment by @DarkRTA
RexSystem 1 vote originally by @DarkRTA on GitHub 1 reply
To be honest, this feels like security theater because nothing stops a server admin from disabling the code and reading their own DB anyway. I guess you could get marginal security improvements in the event of a compromise but I doubt this would be possible to scale up in a secure manner.
Comment by @tsubus
RexSystem 1 vote originally by @tsubus on GitHub
yes but it would only be possible to people with access to the encryption keys, which if done correctly (on the main instance) should be just a select few people (vault admins for example), not everyone with access to the database. encryption at rest is definitely helping securing data. on smaller self hosted instances you just have to trust the owner, obviously, same as with plaintext.