Encrypt messages at rest

(#967) Feature Declined privacy security

Thread

Comment by @DarkRTA
RexSystem 1 vote originally by @DarkRTA on GitHub 1 reply
To be honest, this feels like security theater because nothing stops a server admin from disabling the code and reading their own DB anyway. I guess you could get marginal security improvements in the event of a compromise but I doubt this would be possible to scale up in a secure manner.
Comment by @DarkRTA
RexSystem 1 vote originally by @DarkRTA on GitHub
You still run into the issue of the Fluxer instance itself being compromised and either leaking the keys or decrypting the content itself. Encrypting messages at rest may also be incompatible with search since the messages need to be dumped into a meilisearch instance. In general, instead of trusting that Fluxer is actually encrypting messages at rest, you should avoid sending sensitive information on a Fluxer instance outright unless you absolutely trust the people running it with access to that information. Also consider that a government warrant would require an instance operator to decrypt the data anyway.