While encrypted, encryption key for the database is kept as plaintext in a JSON file.
...which is kept right next to the encrypted DB and presumably has the same permissions, so what's the point?
...which is kept right next to the encrypted DB and presumably has the same permissions, so what's the point?
> Write Ahead Log Files - Using the new WAL mode (i.e. PRAGMA journal_mode = WAL;), page data stored in the WAL file is encrypted using the datbase key. Pages in the rollback journal are encrypted using the same key as the main database. Verification: create an encrypted database, start a transaction, make changes, and then inspect the -wal file using hexdump or a similar program.
Even if the user went as far as deleting the json file, it could still possibly be recovered due to the way the FS ‘deletes’ files.