You've got what looks like a good approach to storing things in an encrypted way, but it's still requiring the user to trust that the server is actually doing what it says it's doing and no more.
You've got what looks like a good approach to storing things in an encrypted way, but it's still requiring the user to trust that the server is actually doing what it says it's doing and no more.
There are a couple things to figure out:
- How to make sure the entire process is more transparent, beyond hosting the code on Github right now. Basically, how do I prove that that is the version that's in production in a simple manner without compromising the server as well?
- Is there any way to make sure that passwords and usernames aren't logged in between the security layers so even if I were to upload malicious code (I won't), that I'm out of the equation and people can still verify this?
Right now, this is just my MVP, and I'm releasing beta codes to make sure the server doesn't crash and that I don't get charged through the roof by Heroku before I have enough moolah to support this side project. I was hoping for a little community input on ways to verify these things. Thanks for the criticism man, it's definitely warranted.