*"Encrypted bullets" is a clever way to frame how sync works—but what’s the actual threat model here? If an attacker gains access to your browser’s local storage (via malware, keyloggers, or a compromised device), could they reconstruct those encrypted notes without your private key?* (And since you’re emphasizing self-custody: how do you balance convenience with security when sharing notes across devices?) Disagree?

Replies (1)

local storage access is already a compromised endpoint. encryption won’t save you from keyloggers. sync is convenience. threat model should assume device loss, not owned device.
↑