https://security.stackexchange.com/questions/30193/encryptin...
Although this approach still requires trust that service providers do indeed encrypt user data.
- HN discussion: https://news.ycombinator.com/item?id=25989698
- A great article about the project: https://ruben.verborgh.org/blog/2020/12/07/a-data-ecosystem-...
I have a saying that the platform should be able to run on a Raspberry PI.
One of my personal pet peeves working with the team is to be able to disappear without impacting them, and it has become the same with our platform: it must be able to disappear users having to scramble to exfiltrate or export their work or data from our infrastructure, because it simply is not there.
E2E encryption avoids that by not trusting whatever is running on the servers Local DBs avoid that by not giving up local data.
However, it would be quite interesting to have a way to remotely know that a certain service is running the code you think it's running.
It sure would, and it would be a hell of a discovery if someone could come up with it. Because I sure can't think of a way that I can't easily debunk.