Hacker News new | past | comments | ask | show | jobs | submit login

It might work, if you truly trust whoever signs up. The fundamental issue is that there's just one encryption key for the whole database, and you need to provide it to everyone who you want to have access to encrypted data. If you stop trusting someone for any reason your only recourse is re-encrypting the entire database, which is a painful offline operation. (You might also be able to support multiple encryption keys -- one per user, say -- but the library isn't really set up to make that convenient right now.)



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: