• 13 Posts
  • 1.37K Comments
Joined 3 years ago
cake
Cake day: July 2nd, 2023

help-circle




  • It doesn’t. The code your site provides is downloaded by your client’s browser. It uses a key on their side that is never sent back to your server. Same as if you did it with an extension or application. This is well trodden ground, and used across the internet such that hosts have zero knowledge of their users’ data aside from in its encrypted state.


    Actually, let me give a little ground here. There is a subtle but real benefit to an extension or signed application. With just JavaScript, a server could on a new page load deliver an altered code that would introduce a compromise. If that is the threat you want to mitigate for, you’re onto something. If you’re talking high stakes, and you make it clear this is the threat for which you’re protecting users, then I could be convinced.








  • Sort of, but it isn’t in my view very well deserved. There is certainly quite a bit of FUD here in the fediverse, but sometimes it feels manufactured.

    The CEO has made, and partially walked back, some statements favoring right wing groups, but it was mostly antitrust stuff, so I think it is mostly rich person doing rich person things.

    But they claim to be politically neutral, and they are a Swiss company which already puts it in a tier above anything hosted in many other western countries.

    The services themselves are technically very well done, and the applications for using them are also very good. They have a new drive cli which is good. The password manager is great. VPN is good too. The mail bridge they provide is also very good if you want to use third party mail apps but with the benefit of their encryption.

    There are other services that compete strongly on each of those and more, but I don’t think any do when considering the full suite.