The short version
Miuchio is a shared photo album for a small group. Your photos are locked on your phone before they are uploaded, and only the people in the album have the keys to unlock them. The server stores the locked photos and makes everyone follow the album's rules, but it is never given those keys.
I also built it so the server learns as little as possible about you. It never sees your name, it does not store your email address, and I kept what it records about who shares albums with whom as small as I could.
Why I built it this way
Photos of the people close to you are some of the most personal things on your phone. So is the list of who you share them with. A normal photo service can look at both, and so can anyone who gets hold of a copy of its database.
Miuchio is my attempt at a shared album where the server cannot see your photos, and where a leaked copy of the database reveals as little as possible about who you are and who you know. The pages here describe how far that goes, and where it stops.
Your phone makes its own keys
When you first sign in, the app creates a set of keys on your phone. Each key has a public half and a private half. The public halves are sent to the server so other people can reach you, a bit like a mailing address. The private halves never leave your phone.
Some of those public keys exist so that someone can send you something while your phone is switched off. The server holds them until someone needs them.
An album has its own key
Alice creates an album called Picnic. Her phone makes a random key for it, the album key. Every photo in Picnic is ultimately protected by that key.
An album goes through numbered stages called epochs, and each epoch has its own album key. A new epoch starts whenever someone leaves. Everyone keeps every epoch key they are given, so old photos stay viewable.
Inviting someone
Everyone has a Miuchio ID, a random 8 character code. Nobody can find you by your email or phone number. People add you with your Miuchio ID.
When Alice invites Bob and Carol with their IDs, her phone locks every one of Picnic's album keys for each of them and sends them in one go. Only Bob's phone can unlock Bob's copy, and only Carol's can unlock hers. So they can see the whole album, including photos added before they joined.
Adding a photo
When Alice adds a photo to Picnic, her phone:
- makes a clean copy of it, without the location, camera model or other hidden details,
- makes a small preview for the album grid,
- locks the photo and the preview, each with its own brand new key,
- locks those two small keys with Picnic's current album key,
- uploads everything in locked form.
Before the server accepts the photo, it checks that the photo's keys are marked with the album's current epoch and that no new epoch is owed. If the app is closed halfway through, the locked copy is already saved on Alice's phone and the upload continues next time.
Bob opens the photo
Bob's phone downloads the locked photo and its locked key. It uses its copy of the album key to unlock the photo's key, then unlocks the photo. If a single byte was changed along the way, the photo refuses to open instead of showing something wrong.
Unlocked photos are kept on Bob's phone so they load quickly next time, but they are locked again with a key that belongs to that phone.
When someone leaves
When Alice removes Carol, the server stops answering Carol's requests for Picnic straight away. Download links it gave her earlier can keep working for up to 30 minutes, but only for photos she could already open. Alice's phone then starts a new epoch with a new album key and gives it only to the people who remain. Photos added after that use the new key, so Carol cannot open them even if she somehow got a copy.
Between those two moments the server refuses new uploads to Picnic, so it never accepts a photo marked with the old epoch. Each phone's uploads continue on their own once the new epoch is in place and that phone has received the new key.
Today only Alice, as the admin, can make the new key, so if her phone is away, uploads stay paused until it comes back. Letting any member make it is what I'm working on next.
Making sure Bob is really Bob
The keys for other people come from the server. So there is one thing encryption alone cannot rule out: a dishonest server handing Alice its own key instead of Bob's the very first time. After that, Alice's phone remembers Bob's key and warns her if it ever changes.
To check that first time too, Alice and Bob can compare a 30 digit safety number, in person or on a call. If both phones show the same number, they have each other's real keys.
What the server avoids knowing
- Your email address is not stored. The server receives it each time you sign in, to send the code, but keeps only a scrambled fingerprint of it: enough to recognise you next time, not enough to read the address back.
- You have a separate ID in every album. Inside each album you appear as a random member ID, different from the one in every other album. The server does keep one shared marker across your memberships so it can list your albums, so a database copy can tell that the same unnamed person is in several albums.
- The link between you and your albums is locked. The database does not store which account a membership belongs to in a readable form. Reading it needs a key the running server holds and the database does not. One exception: an admin's signatures can be matched to their account. That account has no name or email in it, so a copy can tell that the same unnamed account runs certain albums, not who that person is.
- Names, profile photos and album titles are encrypted. Only people in the album can read them.
- Times are rounded. Most times the server records are rounded down to the hour, so a database copy does not show that two people joined within the same minute.
What this does not hide is listed on What Miuchio does not protect, and the reasoning is on Metadata and the social graph.
Practical limits
- An album holds up to 10 people for now. I will raise the limit if people need more.
- Each album has one admin, the person who created it. Only they can invite, remove and start a new epoch. Co-admins, and handing an album over to someone else, are planned.
- If someone leaves while the admin's phone is away, uploads to that album pause until it comes back. Why, and what I'm working on next.
- There is no backup and no second device yet. Reinstalling the app or losing your phone means losing access to your albums. Backup is planned.