At most it should be a thin client.
At most it should be a thin client.
Really? Every kind of server? I'm sorry, but that's some ridiculous statement.
A device running proprietary software that governments have physical access to (after it was confiscated) is less vulnerable than (possibly) your own device running open source software that nobody except you has physical access?
I've edited previous comment.
And if we are being completely paranoid, then you can have some form of Dead man's switch or "self-destruct" option. You have a right to make a phone call, right?
> Currently working on a server in Chrome that you can connect to using node.js to make a web page do stuff (and no, that isn't back to front).
?!?!
I have no words.
It'd be stupid, but there's no reason why you couldn't use a system like that, running in Chrome, listening on an IP address, to do pretty much anything a "real" server does. The user wouldn't know. It's just a server, or "the cloud".
You are naive if you think any device is secure against a determined and well funded actor.
Let me remind you, than if I'm not mistaken in US law enforcement can search your phone without any sort of warrant. Let's assume that you keep your stuff just on your own PC at home, then that at least would require a warrant.
not if it has a password
I think it certainly could be and probably is. Apple seems to be taking phone security pretty darn seriously with combined hardware/software approaches.
Furthermore, my servers sit in a datacenter or my apartment that I rely on somebody else to look after. Really though, you could probably bribe/threaten/warrant your way into those places easily enough and just pull RAM/HDDs to your heart's content. On the flip side, my phone stays in my pocket or next to my bed. If you want my phone, you have to arrest me/steal it from me/whatever.
> US law enforcement can search your phone without any sort of warrant
During a lawful arrest, and the search has to be documented and relevant to the arrest. Furthermore, that assumes that they know my password (Which I'm not currently obligated to give to them).
There's no guarantee it still going to be secure in the future and there's no guarantee that it was secure in the past.
But I'd say to look at how people hiding their money from their governments are doing it. Or look at Snowden. Let the law help you, even if it is the law of another country.
In any case you can create an encrypted container locally and then upload it to a remote server, doesn't really matter that it was intercepted.