Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Are there any encryption information for non-coders? #14829

Closed
GoetheG opened this issue Jun 19, 2019 · 1 comment
Closed

Are there any encryption information for non-coders? #14829

GoetheG opened this issue Jun 19, 2019 · 1 comment

Comments

@GoetheG
Copy link

GoetheG commented Jun 19, 2019

Hi there,

I am a non-coder and I subscribed for a Rocket.Chat service from a German provider. We chose Rocket.Chat as a secure solution for internal communication. Unfortunately, I don't understand what's encrypted in this software and what is not. How secure is it? And what part of my communication can be read by thee provider?

Due to the fact that encrypting data is one of the most important issues in the technological industry now, I'd be happy if there were a clear overview about the encryption and security in Rocket.Chat. A possible solution for that, is not publishing a whitepaper, but it's publishing a clear graphic with explanation on the Rocket.Chat website. We non-coders need to understand what we are subscribing for here :).

There is a website, but it doesn't have any information about the encryption status (currently alpha), encryption stength, what can be encrypted and what effects encryption have on the user experience.
www.rocket.chat/security

Would be nice if the Rocket.Chat team would publish that information in a user friendly way.

Yours

@GoetheG GoetheG changed the title Are there any encryption information for non-codes? Are there any encryption information for non-coders? Jun 19, 2019
@reetp
Copy link

reetp commented Jun 19, 2019

@rocket-cat close

This is a support question rather than a bug.

You may be a non coder, but you don't need to be a coder to learn something about encryption and security in general terms, and be able to read and understand some of this yourself (Open Source is about helping yourself)

Even if Rocket published a lengthy paper, would you be able to understand it, and the ramifications? It is a massive subject and can be highly technical. I am sure they will publish some more details as time goes along, but they have concentrated on development over some fine points of documentation.

I would suggest you make a start with reading about SSL which will tell you that conversations on Rocket via https/SSL are protected from the outside world the same was as say logging into your bank. Depending on your level of paranoia will depend on the type of SSL certification you want - and that is a can of worms in its own right. A Government spy department may want better certificates than my company installation !!

E2E encryption. Yes Rocket has that too. Conversations can be digitally encrypted/stored. But that doesn't stop someone looking over your shoulder, or having a screen reader on your desktop. Just because you have read about 'security' doesn't mean that you will know what is secure, and what is not.

However, as a bonus Rocket is pretty GDPR compliant too :-)

You can of course ask some questions in the forums at forums.rocket.chat or in #support at open.rocket.chat where people will happily try and explain some of this too you. But there is no "Security for Dummies" book !!

You can start reading here by searching for encryption:
https://rocket.chat/docs/

You can open a NFR askignfor more docs here:
https://github.com/RocketChat/feature-requests

Or possibly a documentation bug somewhere here:
https://github.com/RocketChat/docs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants