• kalleboo@lemmy.world
    link
    fedilink
    arrow-up
    15
    arrow-down
    1
    ·
    1 year ago

    As for storing the private key you could encrypt it with (a derivative of) the user’s password

    And now every time a user forgets their password and does password recovery, they lose all their DMs.

    E2EE chat is a difficult problem.

    • Amju Wolf@pawb.social
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      1 year ago

      I mean you could just store it encrypted in the database for the basics, and for advanced users allow them to back it up.

      There are tons of ways to improve it, but there is definitely way more you can do without much inconvenience to the users. I doubt losing old DMs is a huge issue when you forget your password…