Encrypt messages at rest

(#967) Feature Declined privacy security

Thread

Comment by @frolleks
RexSystem 1 vote originally by @frolleks on GitHub OP 1 reply
That is correct, but the DB only contains encrypted messages that the admin or anyone else couldn't see by default. The admin is able to see those messages—but through the admin panel where it can be decrypted. Hence, anyone with access to the DB couldn't really see anything. Unless, they have access to the server, where they could inspect the memory to extract the unencrypted data. So to fix that, another solution is to host the chat encryption/decryption service on another server, isolating itself from the others. Then, the client requests the service if there's a new message event in the gateway, and it transmits directly to the client without going through the API or the gateway.
Comment by @frolleks
RexSystem 1 vote originally by @frolleks on GitHub OP
Another problem is that when the server that hosts this gets attacked, this feature would be rendered useless anyways.