← Back to context

Comment by vishnumohandas

5 years ago

- Mature libsodium clients were available across the platforms we were targeting. The APIs seemed well documented and turned out to be a delight to consume.

- There are access control checks in place to revoke access to files from removed album participants. But from a cryptographic standpoint, once your keys have been shared (/compromised), the respective files should be re-encrypted.

Thanks for answering! Regarding the second point, does the application do this automatically or is the user expected to re-encrypt data manually?