Either naive or dishonest. Can't tell which is worse.
The reason end to end encryption exists is to cover the cases which you can't plan for.
For example a rogue employee reading the notes of their partner.
11–20 of 151 posts
Either naive or dishonest. Can't tell which is worse.
The reason end to end encryption exists is to cover the cases which you can't plan for.
For example a rogue employee reading the notes of their partner.
Great explanation of end-to-end encryption, followed by "but we're too lazy to do that." Not going to ever touch Supernotes now.
And yep, partly it is that don't have the time to dedicate to this. There are so many other features that I think would better serve our users than E2EE, so we're prioritizing those for now (table stakes in the notes game are very high). But if I had infinite time at my disposal, I absolutely would add some form of E2EE – though still not sure I'd make it the default as again, there are some things you can't engineer your way out of when you add E2EE.
The one that is most on my mind probably being irrecoverable data loss. If watching the cryptocurrency space over the last few years has taught me anything, it's that even if you beg people to take good care of secret/recovery keys, frequently they don't. And that's for stuff you can sell for actual money.
here is someone who would have loved E2E for his emails (and images in the cloud):
Google refuses to reinstate account after man took medical images of son’s groin https://news.ycombinator.com/item?id=32560361
Given the tendency of large corporations to look into our private stuff, even on personal mobile devices (Hi Apple), encryption seems to be the only remedy. That is the reason why I store my (encrypted) notes with Joplin on my own server at Hetzner and it's the reason why I only buy smartphones which offer sd-card slots, so I can expand local storage instead of relying on someone's cloud storage.
My preference is to not need to care about what I'm pasting into my notes app. As I use the app on mobile, desktop OS and store not only organized content there, but also random thoughts, incl. sensitive content. That's I prefer to have it E2EE and use standardnotes.com (no affiliation, I'm just a happy customer)
Last I knew standard notes hid 2FA behind the paywall. Basic security should not be a pay feature. If they're willing to hang non-paying potential customers out to dry what other questionable security choices are they making? I tried to reason this out with them back when they had a discourse site or forum, I don't recall which it was, and was told, I'm paraphrasing, we're not going to do that and don't ever ask agai…
One other major downside of end-to-end encryption: everything has to be done client-side, and the server becomes very close to a dumb pipe and block storage. (The only parts the server can do anything with are those that aren’t encrypted, so the explicit goal of E2EE is to reduce the server to a dumb pipe and block storage.) Got ten gigabytes of stuff you want to search through? Without E2EE, the server can implement…
One other major downside of end-to-end encryption: everything has to be done client-side, and the server becomes very close to a dumb pipe and block storage. (The only parts the server can do anything with are those that aren’t encrypted, so the explicit goal of E2EE is to reduce the server to a dumb pipe and block storage.) Got ten gigabytes of stuff you want to search through? Without E2EE, the server can implement…
We've been hearing about homomorphic encryption for years, but I haven't seen it applied in a very practical way.
Yes, notes, often containing the most sensitive material of our lives should be encrypted at every stage of the lifecycle.
> Should Your Notes Be End-to-End Encrypted? Yes. That's why I use Joplin (which is free and open source btw) and not some proprietary freemium app that to explains me that I don't necessary need E2E encryption for my notes.
Use case - I want to keep some notes for myself e2e on my laptop & phone but every now and then I'd like to publish a few of them under a pseudonym anonymously on the internet.
One other major downside of end-to-end encryption: everything has to be done client-side, and the server becomes very close to a dumb pipe and block storage. (The only parts the server can do anything with are those that aren’t encrypted, so the explicit goal of E2EE is to reduce the server to a dumb pipe and block storage.) Got ten gigabytes of stuff you want to search through? Without E2EE, the server can implement…
That sounds like a feature...
What a relief!
I'd take it at their word then, trusting random employees at a random corporation, in a world where even police officers routinely get caught snooping at private data unrelated to their work (e.g. girlfriends and such).
/s