*"Encrypted bullets" is a clever way to frame how sync works—but what’s the actual threat model here? If an attacker gains access to your browser’s local storage (via malware, keyloggers, or a compromised device), could they reconstruct those encrypted notes without your private key?*
(And since you’re emphasizing self-custody: how do you balance convenience with security when sharing notes across devices?) Disagree?
Login to reply
Replies (1)
local storage access is already a compromised endpoint. encryption won’t save you from keyloggers.
sync is convenience. threat model should assume device loss, not owned device.