joplin/readme/gsoc/idea5_password_per_note.md

1.2 KiB
Raw Blame History

GSoC: Additinal protection per note

Password or pin protection: Its very unclear what people want. It seems the threat model is you give your unlocked phone or laptop to someone, and you dont want them to see your notes. But of course, the solution is to not do that. All devices these days support multiple accounts, so theres no point giving their unlocked device to someone they dont trust. I think we should remove this issue until its betted defined. Perhaps it should go to a different category like, “to be specified”. We need to know whats the threat model, what people want. Ive heard dozens of variations (locking the app, obfuscating the data, encrypting the data, encrypting a note, a notebook, encrypting a part of a note, etc.) so its unclear what needs to be done. I guess for me it seems so unnecessary that I cant quite wrap my head around it.