I'm developing a small private social network where the users can share media files and text with each other. To provide some sort of security the data is stored encrypted on the server / in the database. Now the question is where and how to store the private key(s) of the encrypted data. I use mongoDB to store the user information and a simple Apache 2 server to store the actual encrypted media files. The client is connected to a socket.io server running on https to read the database content. So here is a list of the steps I thought of to make it as safe as possible, please let me know if I miss something or going down the wrong path.
- AES 128 bit encryption for the media files and text
- HTTPS and SSL encryption for the Server-Client connection
- Storing the secret key for the database content in a c / c++ class (if possible?) in the client code
- Creating an own secret key for every media file / upload and storing it encrypted in the database
- Restrict the access to the server to everything but the encrypted media files