RexSystem1 voteoriginally by @DarkRTA on GitHub1 reply
To be honest, this feels like security theater because nothing stops a server admin from disabling the code and reading their own DB anyway.
I guess you could get marginal security improvements in the event of a compromise but I doubt this would be possible to scale up in a secure manner.
RexSystem1 voteoriginally by @frolleks on GitHub OP
Encrypting messages at rest may also be incompatible with search since the messages need to be dumped into a meilisearch instance.
Thanks for the heads up.
Like what I said in the other comment, it can call the chat encryption/decryption service to decrypt the chats that is then dumped into Meilisearch.
...you should avoid sending sensitive information on a Fluxer instance outright unless you absolutely trust the people running it with access to that information. Also consider that a government warrant would require an instance operator to decrypt the data anyway.
I would think that if federation was implemented—specifically identity federation, and the guilds are hosted in different servers, this wouldn't really be a problem. (Which somehow also renders the feature I requested useless? It's not a problem though, I'm just trying to find out whether this feature is viable or not in the long term via this discussion.)
Thread
Comment by @DarkRTA
Comment by @frolleks