Symmetric encryption over HTTPS: one bearer token, one call per operation, and no key rings or IAM policies to set up.
Hello, I’m looking for some criticism. I’m also looking for some people to help test this service.
2 comments
annrap1d5 days ago
This is really nicely done. One question. Since you state 'this is not zero-knowledge' because plaintext briefly hits your API over HTTPS, what precise architectural isolation protects that plaintext in memory while it is being encrypted?
levidurfee5 days ago
That's an excellent question! It's currently running on Google Cloud Run, which to my knowledge, doesn't offer any encrypted memory options. So, as of now, there isn't any architecture in place to protect the plaintext.
It's definitely something we've thought about. And something we may pursue.
Read the full thread on Hacker News →
Related stories
- Hacker News · 1 points · 6 days ago
- Hacker News · 1 points · 1 day ago
- Hacker News · 1 points · 4 days ago
- Hacker News · 1 points · 10 days ago
- Terminally confused (2012)spin0r.wordpress.comLobsters · 2 points · 5 days ago
- Hacker News · 421 points · 6 days ago