End-to-end encryption: hold the position #72
Labels
No labels
area:docs
area:identity
area:ops
area:plugin
area:server
channel:community
channel:direct
channel:owned
channel:press
channel:social
e2ee-constrained
gate:at-ga
gate:pre-ga
marketing
parity
relay:absent
relay:planned
relay:requested
relay:supported
risk:additive
risk:contract
risk:none
usability
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
Nectenda/nectenda#72
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Part of #37. Filed to hold the position, not to build anything.
Status at Relay
Considering — their least-committed roadmap tier. Classified
relay:requestedrather than
relay:absentfor exactly that reason: it has been asked for, loudlyand publicly, and they have not committed.
Their own documentation: "Relay isn't end-to-end encrypted, we have the
technical ability to access synced content if required." On their forum thread a
user with ~30,000 notes asked directly about AI training and what happens on
acquisition; the founders answered that they have no interest in reading user
content and that E2EE is planned "once complexity decreases".
The live objection against them, in their own thread: "I would have to upload my
vault to your server with no privacy guarantees."
Why it is a durable difference
Retrofitting E2EE is not a sprint for them. Server-side permissions, search and
previews all assume readable plaintext — and this backlog is itself evidence of
the cost, since half its
e2ee-constrainedissues describe features that arecheap for them and shaped differently for us.
What this issue guards
That the claim stays exactly true as the product grows. Per
docs/positioning.md, never say "zero knowledge", never "audited", never "westore no metadata", never "open source", never "more secure than Obsidian Sync".
docs/security-model.mdis written to be checked against the client, andCLAUDE.mdrequires that a change weakening the encryption story be reflectedthere and not only in the code.
Also worth recording
Relay currently has three open, maintainer-reproduced data-corruption bugs —
#135 (disk edits merged at wrong offsets, corruption propagates), #136 (a
rename deleting a member's note and writing broken links) and #137 (a 0-byte
file reported as "Synced"). #137 is exactly the failure mode
CLAUDE.mdcallsthe worst one.
Record it as sourced fact. Do not campaign on it — per
docs/positioning.mdthe durable claim is the encryption, and bugs are weather.Risk
risk:none.Moved to the Vikunja board as NEC-48: https://projectron.nerchure.com/tasks/48