Encrypt messages at rest

(#967) Feature Declined privacy security

Thread

Comment by @DarkRTA
RexSystem 1 vote originally by @DarkRTA on GitHub 1 reply
To be honest, this feels like security theater because nothing stops a server admin from disabling the code and reading their own DB anyway. I guess you could get marginal security improvements in the event of a compromise but I doubt this would be possible to scale up in a secure manner.
Comment by @DarkRTA
RexSystem 1 vote originally by @DarkRTA on GitHub
Federation actually makes the problem of trust worse because now you need to trust random instance operators to not snoop through messages rather than a single organization. The thing about government warrants still applies too, but at a smaller scope.