How MindMapVault Combines SSO with Zero-Knowledge Encryption Using Device Keys
MindMapVault, a browser-based encrypted notes app, has implemented single sign-on (SSO) without surrendering its zero-knowledge encryption model. The app derives a master encryption key from the user's passphrase entirely in the browser using Argon2id, meaning the server only ever sees a hashed authentication token and encrypted ciphertext. Rather than using key escrow — the common but privacy-compromising approach many 'end-to-end encrypted' SSO products silently adopt — MindMapVault relies on the user's passphrase for first-time setup and a stored device key for subsequent logins. This means users type their passphrase only when setting up a new device, while everyday sign-ins flow through the identity provider without any passphrase prompt. The trade-off is explicit: there is no account recovery mechanism, so losing all trusted devices and forgetting the passphrase results in permanent loss of vault data.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in