Data encrypted at rest?
Les mainteneurs répondent en général sous 1 jour
@cameri y travaille déjà.
Depuis le 21/3/2023.
Évaluation
Cette issue n'a pas encore été évaluée.
Description
My host just about has nostream installed and running and this morning I started wondering if nostream is compliant with GDPR, California's privacy law, etc.
npubs are literally personally identifiable information. Events absolutely have personally identifiable information. The users table - well, that's about users so that's all personally identifiable information. The invoices table is tied to people so that also contains personally identifiable information. At the end of the day social media databases are the poster children for databases with personally identifiable information. Everything related to a person (nym or real name) has to be encrypted.
The problem is, unlike MySQL / MariaDB, PostgreSQL doesn't seem to do "encryption at rest".
https://www.postgresql.org/docs/current/encryption-options.html
If I understand it correctly the options are:
- Encrypting the entire drive - but that's not really "encrypted at rest" since any application with proper permissions can read anything on the drive. It only helps if the drive gets physically stolen (which isn't really a problem in modern data centers).
- Particular columns can be encrypted but then the clients accessing those columns have to futz with keys when it accesses the data.
From what I'm seeing there's no equivalent of MySQL/MariaDB's encryption of tables/tablespaces.
SO… Are there any plans to support MySQL/MariaDB? I don't see how I (or anyone for that matter) can use nostream until it supports a database that can encrypt data at rest.
Sorry for being a bummer. But I've survived this long doing what I do because I fuss over details like this. (And my users trust me with truly sensitive information because I fuss over details like this).
- Langage dominant
- TypeScript
- Étoiles
- 829
- Forks
- 234
- Merge moyen
- 4 j 5 h
- PR mergées (30 j)
- 22
Préparer son environnement
- Fournit un Dockerfile ou un fichier Docker Compose
- Propose un modèle de pull request
- Lire le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Autres issues de cameri/nostream
-
Difficulté 2/5 1-3 heures Accessibilité débutants 82/100
cameri/nostream#811 · 1 commentaire ·
Les mainteneurs répondent en général sous 1 jour
-
Difficulté 2/5 1-3 heures Accessibilité débutants 72/100
Les mainteneurs répondent en général sous 1 jour
-
feat(nip77): negentropy reconciliation core for the PostgreSQL backendPeut-être pris @Priyanshubhartistm l’a pris il y a 3 jours. Ouverteenhancement
cameri/nostream#801 · 1 personne assignée ·
Les mainteneurs répondent en général sous 1 jour
-
feat(admin): bounded NIP-66 probe history and Network Health timelinePeut-être pris @Ferryx349 l’a pris il y a 3 jours. OuverteAdmin Console enhancement
cameri/nostream#800 · 1 personne assignée ·
Les mainteneurs répondent en général sous 1 jour
-
Store relay settings overrides in PostgreSQL (SETTINGS_BACKEND=db)Peut-être pris @Ferryx349 l’a pris il y a 36 jours. Ouverteenhancement
cameri/nostream#757 · 1 personne assignée ·
Les mainteneurs répondent en général sous 1 jour
Toutes les issues de cameri/nostream
Issues similaires
-
submodule-pointer-regression
Difficulté 1/5 Moins d'une heure Accessibilité débutants 72/100
smith-horn/skillsmith#3061 ·
Les mainteneurs répondent en général sous 1 jour
-
area: ops type: test
Difficulté 2/5 1-3 heures Accessibilité débutants 79/100
accensa/x402-facilitator-stellar#559 ·
Les mainteneurs répondent en général sous 1 jour
-
Fix the no-pin ruling in line-drawings: pin a below-the-record stage at the record's chapterOuvertedocumentation
Difficulté 2/5 1-3 heures Accessibilité débutants 74/100
cosimochellini/one-piece-zero-spoiler#551 ·
Les mainteneurs répondent en général sous 1 jour
-
getWatched() omits __proto__ directories when cwd is setPeut-être pris @maxazure l’a pris aujourd’hui. Ouverte
Difficulté 2/5 1-3 heures Accessibilité débutants 79/100
-
area:web enhancement
Difficulté 2/5 1-3 heures Accessibilité débutants 84/100
Les mainteneurs répondent en général sous 1 jour