this post was submitted on 10 Apr 2024
70 points (93.8% liked)
Privacy
31783 readers
515 users here now
A place to discuss privacy and freedom in the digital world.
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
Some Rules
- Posting a link to a website containing tracking isn't great, if contents of the website are behind a paywall maybe copy them into the post
- Don't promote proprietary software
- Try to keep things on topic
- If you have a question, please try searching for previous discussions, maybe it has already been answered
- Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
- Be nice :)
Related communities
Chat rooms
-
[Matrix/Element]Dead
much thanks to @gary_host_laptop for the logo design :)
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Is there anything won't with the company itself being in Pakistan, if it's explicitly hosting your data in Germany? I'm not aware of any nation-level threat going on over there, and their client is open-source on all platforms, so I don't imagine there's much that would be compromised.
Idk, maybe I'm wrong. Notesnook is recommended by privacyguides at all. All my mistrust comes from the fact that such countries are not famous for respecting human rights. What if the government forces the owners to give up the keys? Maybe it's an unrealistic scenario cause data is encrypted.
You're asking the right questions.
Regarding keys: they never store those. If they did, that would be a problem from the beginning. The whole point of E2EE encryption is that the servers and server owners should never be able to access your data even if you wanted them to.
Yes, you had me cause I write only about keys, but I thought also about backdoors on gov demand.
If you're worried about backdoors, you can build every client from source and verify the code. IIRC they haven't paid for an audit, but if they failed to protect your passwords/keys that'd be really bad for their reputation. And considering their target demographic, it's pretty important to keep that part of the reputation alive.
Notesnook is open source and you can check (if you have the knowledge) if there are any issues. They're working on making the server self-hostable (also fully open source) so there's that.