RexSystem1 voteoriginally by @DarkRTA on GitHub1 reply
To be honest, this feels like security theater because nothing stops a server admin from disabling the code and reading their own DB anyway.
I guess you could get marginal security improvements in the event of a compromise but I doubt this would be possible to scale up in a secure manner.
RexSystem1 voteoriginally by @frolleks on GitHub OP
> Like what I said in the other comment, it can call the chat encryption/decryption service to decrypt the chats that is then dumped into Meilisearch.
I do not believe this solves anything though, as you'd be dumping plaintext messages into Meilisearch, which makes message encryption pointless. Meilisearch becomes its own attack surface, and an attacker wouldn't even need DB access to get to the plaintext. So what would encrypting the messages in the database actually solve here?
Thanks for the heads up.
Another thing to point out other than Meilisearch becoming its own attack surface, although regardless if it is or not, is that plaintext access from a bad actor would still be possible as the decrypted chat would be transmitted over the network.
Initially, I haven't really thought of the side effects that would affect the other services required for running Fluxer properly. Hence, I thought that this would decrease the possibility of chats being leaked.
But after some consideration, this seems to add another layer of complexity which ends up being the same thing compared to if this feature wasn't implemented at all.
Thread
Comment by @DarkRTA
Comment by @frolleks