76
MeroChat - Open Source Random Chat
(mero.chat)
All about open source! Feel free to ask questions, and share news, and interesting stuff!
Community icon from opensource.org, but we are not affiliated with them.
Yeah, I'm not used to E2EE in the browser either and StackExchange seems to agree that there's no nice solution :/
The sanest option in terms of user practicality to me appears to be storing the private key on the server, maybe encrypted with the user's password, and sending it to the user on successful login where it would be decrypted client side. It seems like it's more or less what Mega is doing since they have a similar issue
If the server having temporary access to the user's password is an issue maybe the password could be partially pre-hashed before being sent?
It's be interesting to talk about it with someone with more experience, especially since implementing all of that will be a pain so it can't be redone every Thursday