Hacker News new | ask | show | jobs
by dns_snek 743 days ago
Encrypting the data with a key that's stored on - or only accessible using a hardware token like a YubiKey would be a good start. That way the data can't be decrypted without explicit user action.