|
|
|
|
|
by Closi
171 days ago
|
|
I think the challenge is that you are potentially storing some of the most secret things for users here - passwords copied from password managers, bank details copied and pasted into forms, private photos, corporate secrets and designs, medical records... And even your revised model shows a completely careless approach to security and is entirely insufficient considering the data stored. Encrypting images is too slow too? Poor excuse - it probably takes milliseconds. If you are asking people to trust them with their nudes and photos of bank documents, you need to store them in a way that you can’t see them. You having access to all user data stored with a tiny privacy policy that basically boils down to “we can use your data as long as it’s not illegal for us to use it” is not sufficient! I wouldn’t be this harsh on the security of another startup or app just because most startups don’t start asking users to store their secrets with them - because you will be storing secrets, that puts you into a category of people who need to be careful and not careless - at the moment you are demonstrating the latter. It’s entirely possible to do everything end to end by the way (imo this is the only way this should be done considering you will be storing passwords) - see how 1password does it and copy them if nothing else: https://1password.com/files/1password-white-paper.pdf |
|