End-to-end encryption: hold the position #72

Closed
opened 2026-09-21 18:07:08 +01:00 by cruelacid · 1 comment
Owner

Part of #37. Filed to hold the position, not to build anything.

Status at Relay

Considering — their least-committed roadmap tier. Classified relay:requested
rather than relay:absent for exactly that reason: it has been asked for, loudly
and publicly, and they have not committed.

Their own documentation: "Relay isn't end-to-end encrypted, we have the
technical ability to access synced content if required."
On their forum thread a
user with ~30,000 notes asked directly about AI training and what happens on
acquisition; the founders answered that they have no interest in reading user
content and that E2EE is planned "once complexity decreases".

The live objection against them, in their own thread: "I would have to upload my
vault to your server with no privacy guarantees."

Why it is a durable difference

Retrofitting E2EE is not a sprint for them. Server-side permissions, search and
previews all assume readable plaintext — and this backlog is itself evidence of
the cost, since half its e2ee-constrained issues describe features that are
cheap for them and shaped differently for us.

What this issue guards

That the claim stays exactly true as the product grows. Per
docs/positioning.md, never say "zero knowledge", never "audited", never "we
store no metadata", never "open source", never "more secure than Obsidian Sync".
docs/security-model.md is written to be checked against the client, and
CLAUDE.md requires that a change weakening the encryption story be reflected
there and not only in the code.

Also worth recording

Relay currently has three open, maintainer-reproduced data-corruption bugs —
#135 (disk edits merged at wrong offsets, corruption propagates), #136 (a
rename deleting a member's note and writing broken links) and #137 (a 0-byte
file reported as "Synced"). #137 is exactly the failure mode CLAUDE.md calls
the worst one.

Record it as sourced fact. Do not campaign on it — per
docs/positioning.md the durable claim is the encryption, and bugs are weather.

Risk

risk:none.

Part of #37. Filed to hold the position, not to build anything. ## Status at Relay **Considering** — their least-committed roadmap tier. Classified `relay:requested` rather than `relay:absent` for exactly that reason: it has been asked for, loudly and publicly, and they have not committed. Their own documentation: *"Relay isn't end-to-end encrypted, we have the technical ability to access synced content if required."* On their forum thread a user with ~30,000 notes asked directly about AI training and what happens on acquisition; the founders answered that they have no interest in reading user content and that E2EE is planned "once complexity decreases". The live objection against them, in their own thread: *"I would have to upload my vault to your server with no privacy guarantees."* ## Why it is a durable difference Retrofitting E2EE is not a sprint for them. Server-side permissions, search and previews all assume readable plaintext — and this backlog is itself evidence of the cost, since half its `e2ee-constrained` issues describe features that are cheap for them and shaped differently for us. ## What this issue guards That the claim stays exactly true as the product grows. Per `docs/positioning.md`, never say "zero knowledge", never "audited", never "we store no metadata", never "open source", never "more secure than Obsidian Sync". `docs/security-model.md` is written to be checked against the client, and `CLAUDE.md` requires that a change weakening the encryption story be reflected there and not only in the code. ## Also worth recording Relay currently has three open, maintainer-reproduced data-corruption bugs — **#135** (disk edits merged at wrong offsets, corruption propagates), **#136** (a rename deleting a member's note and writing broken links) and **#137** (a 0-byte file reported as "Synced"). #137 is exactly the failure mode `CLAUDE.md` calls the worst one. Record it as sourced fact. **Do not campaign on it** — per `docs/positioning.md` the durable claim is the encryption, and bugs are weather. ## Risk `risk:none`.
Author
Owner

Moved to the Vikunja board as NEC-48: https://projectron.nerchure.com/tasks/48

Moved to the Vikunja board as **NEC-48**: https://projectron.nerchure.com/tasks/48
Sign in to join this conversation.
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
Nectenda/nectenda#72
No description provided.