176 karma · joined April 2, 2013
@moinism
https://moin.im
- Important passwords
- Insurance policies
- Anything owed or lent
- Online subscriptions to cancel
- Bills or loans to pay to avoid late fees
- Any information that your business partners would want to know
- Contact information for other important people in your life, such as close friends
- Any accounts or assets that you have and the login information for them
- Special instructions or wishes
Are you by any chance hiring global-remote, full-stack/front-end devs? Would love to work with you guys.
I'll fix the privacy policy right away. Thank you for pointing it out.
The note data is encrypted at-rest. The encryption keys are kept separate. Which means even if the whole database gets leaked/hacked, the note details won't be readable.
I plan to pursue SOC 2 certification, to give users peace of mind regarding snooping, etc., if I get some signs of product-market-fit.
But if the recipient forgets the password? They won't be able to reset it, in most case either, because the reset link goes to the original email which the recipient may not have access to.
The note is stored in the DB after its encrypted. What do you suggest I change to make it more secure?
The note is stored encrypted using AES 256-bit keys. The only time it's decrypted without your credentials is when you don't login during the check-in period.
I also want to make it end-to-end encrypted (still looking into it) but that has a UX problem. If the recipients need a key to decrypt it, a new problem of keeping the key safe and not forget about it also appears. And if we keep the key on our server then it also kills the whole point of e2e.
I'd love to know any change I can make to make your more confident in it?
All the information your write in your note is encrypted using 256-bit AES key. Encryption keys and the data itself are stored in different services. So even if the database is leaked/hacked, the information will not be public.
It works as a "dead man's switch". As long as you sign in at least once a month your note will be stay private. Otherwise, your designated recipients will get it in the email.
Why:
1. The logo icon is almost always from a service like The Noun Project. Probably fetched with 'category' of the company user enters. If it's not an icon then the first letter of the company name, why not?
2. The generated logo has the company name in different combinations of fonts, background and foreground colors. A simple algorithm with random value selection can do that. Where's AI in that?
Either AI is not being used at all or not to its full potential at least.
Why don't I see a logo for my product that has an icon like, say Airbnb's "A" or Apple's "Bitten Apple". All I get for my tech product are small mobiles and browser windows.
Is it open-source?
You can also use this to create the UI: https://github.com/botui/botui