Data encrypted at rest?
維護者通常 1 天內回覆
@cameri 已經在處理了。
開始於 2023年3月21日。
評估
這個 Issue 還沒有評估資料。
描述
My host just about has nostream installed and running and this morning I started wondering if nostream is compliant with GDPR, California's privacy law, etc.
npubs are literally personally identifiable information. Events absolutely have personally identifiable information. The users table - well, that's about users so that's all personally identifiable information. The invoices table is tied to people so that also contains personally identifiable information. At the end of the day social media databases are the poster children for databases with personally identifiable information. Everything related to a person (nym or real name) has to be encrypted.
The problem is, unlike MySQL / MariaDB, PostgreSQL doesn't seem to do "encryption at rest".
https://www.postgresql.org/docs/current/encryption-options.html
If I understand it correctly the options are:
- Encrypting the entire drive - but that's not really "encrypted at rest" since any application with proper permissions can read anything on the drive. It only helps if the drive gets physically stolen (which isn't really a problem in modern data centers).
- Particular columns can be encrypted but then the clients accessing those columns have to futz with keys when it accesses the data.
From what I'm seeing there's no equivalent of MySQL/MariaDB's encryption of tables/tablespaces.
SO… Are there any plans to support MySQL/MariaDB? I don't see how I (or anyone for that matter) can use nostream until it supports a database that can encrypt data at rest.
Sorry for being a bummer. But I've survived this long doing what I do because I fuss over details like this. (And my users trust me with truly sensitive information because I fuss over details like this).
- 主要語言
- TypeScript
- 星號
- 829
- 分支
- 234
- 平均合併
- 4 天 5 小時
- 30 天內合併 PR
- 22
環境準備
- 提供 Dockerfile 或 Docker Compose 檔案
- 有 Pull Request 範本
- 閱讀貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
cameri/nostream 的其他 Issue
-
難度 2/5 1-3 小時 新手友好度 82/100
維護者通常 1 天內回覆
-
難度 2/5 1-3 小時 新手友好度 72/100
維護者通常 1 天內回覆
-
feat(nip77): negentropy reconciliation core for the PostgreSQL backend可能已有人在做 @Priyanshubhartistm 於 3 天前認領。 未關閉enhancement
cameri/nostream#801 · 已指派 1 人 ·
維護者通常 1 天內回覆
-
feat(admin): bounded NIP-66 probe history and Network Health timeline可能已有人在做 @Ferryx349 於 3 天前認領。 未關閉Admin Console enhancement
cameri/nostream#800 · 已指派 1 人 ·
維護者通常 1 天內回覆
-
Store relay settings overrides in PostgreSQL (SETTINGS_BACKEND=db)可能已有人在做 @Ferryx349 於 36 天前認領。 未關閉enhancement
cameri/nostream#757 · 已指派 1 人 ·
維護者通常 1 天內回覆
相似的 Issue
-
by: ai-assisted frontend good-for: new-member spike
難度 2/5 1-3 小時 新手友好度 68/100
Northeastern-Electric-Racing/Argos#847 ·
維護者通常 4 天內回覆
-
難度 1/5 1-3 小時 新手友好度 84/100
SignalK/freeboard-sk#990 ·
維護者通常 1 天內回覆
-
[missing-inheritance] audit review (1 preset)可能已有人在做 @github-actions 今天認領。 未關閉
難度 1/5 1 小時以內 新手友好度 82/100
osmberlin/tagging-schema-browser#363 · 1 則留言 ·
維護者通常 1 天內回覆
-
enhancement
難度 2/5 1-3 小時 新手友好度 68/100
Albert-Weasker/niubigeo#205 ·
維護者通常 1 天內回覆
-
area/frontend area/v2 kind/bug priority/needs-triage
難度 2/5 1-3 小時 新手友好度 70/100
kubeflow/notebooks#1498 · 1 則留言 ·
維護者通常 1 天內回覆