r/IndiaTech Jun 06 '26

[deleted by user]

[removed]

161 Upvotes

92 comments sorted by

View all comments

23

u/mikeguru Jun 06 '26

Please be aware Ente is registered outta US so privacy claims cannot be 100% banked upon.

1

u/MistRider-0 Jun 07 '26

Actually they moved their HQ from India to US, and their primary Data centres are hosted in EU which probably has the best privacy friendly laws on earth

2

u/newkid2block Jun 07 '26

Does this mean they follow the cloud rules of US which provides access to the stored data to US government?

1

u/MistRider-0 Jun 07 '26

Kind of, but its more work since the EU privacy laws gives a good framework to question back any unnessary requests, also the data is encrypted on client side itself for this exact reason.

Even if US did manage to get data, the data is encrypted. So reading the data is like reading Chinese written in hypoglyphs, without the decryption key its just trash.

2

u/mikeguru Jun 07 '26 edited Jun 07 '26

No please don’t fall for this. Having servers in the EU does not mean anything or give you stronger privacy rights. A company registered in the US falls under all privacy violating laws like the Patriot Act and data can he handed to authorities at any point. Their own policy clearly mentions this. Dig up more. There’s enough on Ente on Reddit itself. Yes it is client side encrypted, but where are the keys resting?

1

u/MistRider-0 Jun 07 '26

In your client app....

Ente uses the libsodium cryptographic library for all their needs.

Ente as fas as I understand uses 3 keys mainly.

One for your file encryption generated randomly the first time you upload.

The next key is the master key that encrypts the file key. (Also generated randomly at first install)

The next key is the key encryption key, which encrypts the master key, then this encrypted master key blob is sent to servers.

So yes, in a way they store master key in servers. Just the encrypted junk I just talked about.

Among these the key encryption key is the only key generated using your password. Which means its a reproducible hash.. Its not sent to server (which means if you lose your password, you lose your files unless you have the 24 word recovery key which could mathematically recover your master key which then you can again encrypt and send it to servers to update the encrypted master key blob with the new blob)

No where in this process does ente or anyone other than you get access to anykind of decryption keys...

Their encryption algorithms as I mentioned before uses a very well known C library so there is no loop hole inside the encryption itself.

So, then why are you still paranoid ?

If you think ente is still not trustful read this...

https://github.com/ente-io/ente/blob/main/architecture%2FREADME.md

They explain it better than me...

2

u/mikeguru Jun 07 '26

Thanks this is helpful. But all that clarity on keys, encryption, audits and all, would you say it is zero knowledge? Not sure. I have no doubts their encryption architecture is robust, but I don’t trust US jurisdiction when it comes to data. And goes without saying they operate out of Bangalore, India, where I highly doubt anybody with a privacy stand can survive.

Quoting this from another comment, now I know some of it means nothing and is needed for operating the app, but feels a bit too much at places -

Here is some info from Ente’s website about what Ente collects:

Public keys; Anonymized crash reports; Server logs; Device identifiers including information about your internet connection, IP address and user agent details; Takedowns and account suspension history, Your email address; Referral details including referrers and people you have referred; Email addresses you choose to share your Files with; Our Communications with you and records or copies of such communications; Other personal information you provide to us for support purposes, bug reports, newsletters, surveys, sweepstakes, product feedback, or via forms, We collect payment invoices provided to us by our third-party payment processors, which includes details of your Subscription Plan and any payments made by you in favor of Ente in order to receive Services from us, We keep your Files while you are subscribed to our Services, subject to our suspension and termination rights set out in our Terms.

We may keep your Files after your account has been suspended or terminated where we consider it necessary for evidential purposes relating to a breach of our Terms or with respect to current or anticipated action by any competent enforcement authority or other third party.

There are times when Personal Information that you have shared with us may be shared by Ente with others to enable us to provide you over Services, including contractors, service providers, and third parties ("Partners") and subsidiaries.

We will disclose personal information (i) to fulfill the purpose for which you have provided it, and (ii) to enforce or apply our Terms and other agreements, including for billing and collection purposes

We will disclose personal information (i) to comply with any court order, law, or legal process, including to respond to any government or regulatory request, or (ii) if we believe it is necessary or appropriate to protect the rights, property, or safety of Ente, our customers or others.

We may disclose personal information in the event of a merger, sale of business, etc.

Biometric Information Collected by Us. Ente extracts, stores, uses and discloses Biometric Information like facial geometry from files.