Data encrypted at rest?
Maintainer antworten meist innerhalb von 1 Tag
@cameri arbeitet bereits daran.
Seit 21.3.2023.
Bewertung
Dieses Issue wurde noch nicht bewertet.
Beschreibung
My host just about has nostream installed and running and this morning I started wondering if nostream is compliant with GDPR, California's privacy law, etc.
npubs are literally personally identifiable information. Events absolutely have personally identifiable information. The users table - well, that's about users so that's all personally identifiable information. The invoices table is tied to people so that also contains personally identifiable information. At the end of the day social media databases are the poster children for databases with personally identifiable information. Everything related to a person (nym or real name) has to be encrypted.
The problem is, unlike MySQL / MariaDB, PostgreSQL doesn't seem to do "encryption at rest".
https://www.postgresql.org/docs/current/encryption-options.html
If I understand it correctly the options are:
- Encrypting the entire drive - but that's not really "encrypted at rest" since any application with proper permissions can read anything on the drive. It only helps if the drive gets physically stolen (which isn't really a problem in modern data centers).
- Particular columns can be encrypted but then the clients accessing those columns have to futz with keys when it accesses the data.
From what I'm seeing there's no equivalent of MySQL/MariaDB's encryption of tables/tablespaces.
SO… Are there any plans to support MySQL/MariaDB? I don't see how I (or anyone for that matter) can use nostream until it supports a database that can encrypt data at rest.
Sorry for being a bummer. But I've survived this long doing what I do because I fuss over details like this. (And my users trust me with truly sensitive information because I fuss over details like this).
- Vorherrschende Sprache
- TypeScript
- Sterne
- 829
- Forks
- 234
- Ø Merge
- 4 T. 5 Std.
- Gemergte PRs (30 T.)
- 22
Entwicklungsumgebung
- Enthält ein Dockerfile oder eine Docker-Compose-Datei
- Hat eine Pull-Request-Vorlage
- Beitragsleitfaden lesen
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus cameri/nostream
-
validateSettings() doesn't validate rateLimits[].period — zero period silently degrades to a 1ms backoff hintEvtl. vergeben Ein verknüpfter Pull Request ist offen oder bereits gemergt. Offen
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100
cameri/nostream#811 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
Maintainer antworten meist innerhalb von 1 Tag
-
feat(nip77): negentropy reconciliation core for the PostgreSQL backendEvtl. vergeben @Priyanshubhartistm hat das vor 2 Tagen übernommen. Offenenhancement
cameri/nostream#801 · 1 zugewiesene Person ·
Maintainer antworten meist innerhalb von 1 Tag
-
feat(admin): bounded NIP-66 probe history and Network Health timelineEvtl. vergeben @Ferryx349 hat das vor 3 Tagen übernommen. OffenAdmin Console enhancement
cameri/nostream#800 · 1 zugewiesene Person ·
Maintainer antworten meist innerhalb von 1 Tag
-
Store relay settings overrides in PostgreSQL (SETTINGS_BACKEND=db)Evtl. vergeben @Ferryx349 hat das vor 36 Tagen übernommen. Offenenhancement
cameri/nostream#757 · 1 zugewiesene Person ·
Maintainer antworten meist innerhalb von 1 Tag
Alle Issues in cameri/nostream
Ähnliche Issues
-
bug cli service
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100
Maintainer antworten meist innerhalb von 1 Tag
-
create-element: same editorAlias silent-fallback bug as #201, not covered by that fixEvtl. vergeben Ein verknüpfter Pull Request ist offen oder bereits gemergt. Offengenerated-by-ai
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
umbraco/Umbraco-CMS-MCP-Editor#208 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
Table: Space fires onActivate in single-selection mode — the reference doc and the JSDoc disagreeOffen
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 68/100
sidorares/react-x11-components#764 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 76/100
backnotprop/plannotator#1840 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
JoviDeCroock/pracht#432 ·
Maintainer antworten meist innerhalb von 1 Tag