Как общие фото шифруются до загрузки
Фото в ленте, в чате и в календаре не загружаются как обычная картинка. Перед отправкой браузер шифрует байты файла и только потом отдаёт их на сервер.
На каждый файл создаётся случайный ключ AES-GCM длиной 32 байта и отдельный вектор инициализации на 12 байт. Этим ключом закрывается содержимое. Наружу уходит непрозрачный блоб, а не JPEG, который можно открыть по прямой ссылке.
Сам ключ файла нельзя положить рядом с блобом в открытом виде. Он сериализуется вместе с вектором и шифруется тем же способом, что и текст чата: ECDH P-256 и AES-GCM, на публичный ключ партнёра. В хранилище остаётся конверт с шифротекстом ключа.
Для календаря конверт делается дважды: для автора и для партнёра. Оба могут расшифровать один и тот же файл своими ключами устройства. Третьей копии ключа у сервиса нет.
Тип файла и размер могут храниться отдельно — по ним нельзя восстановить картинку. Содержимое появляется снова только на устройстве пары, когда браузер расшифровывает блоб ключом из конверта.
Текст сообщения и вложение поэтому защищены по-разному, но одной границей: сервер видит, что файл доставлен, и не видит, что на нём изображено.
How shared photos are encrypted before upload
Photos in the feed, chat, and calendar are not uploaded as ordinary images. The browser encrypts the file bytes first and only then sends them to the server.
Each file gets a random 32-byte AES-GCM key and its own 12-byte initialization vector. That key seals the contents. What leaves the browser is an opaque blob, not a JPEG that opens from a direct link.
The file key cannot sit next to the blob in the clear. It is serialized with the vector and encrypted the same way as chat text: ECDH P-256 and AES-GCM, to the partner’s public key. Storage keeps an envelope of ciphertext, not the raw key.
For the calendar the envelope is made twice: once for the author and once for the partner. Both can decrypt the same file with their own device keys. The service does not keep a third copy of the key.
File type and size may be stored beside the blob. They are not enough to reconstruct the picture. The image appears again only on a couple’s device, after the browser decrypts the blob with the key from the envelope.
Message text and attachments are protected differently, behind the same boundary: the server can see that a file arrived, and it cannot see what the file shows.