Security and permissions
Encryption#
- Each backup gets a random 10-character ID and its own AES-256-GCM key, which encrypts the content and every file individually. The key is derived (HKDF-SHA256, with a random salt per backup) from the bot key - a secret that only whoever runs the bot has, kept outside the database.
- So the database alone reveals nothing: a stolen database dump is unreadable without the bot key. Whoever runs the bot, on the other hand, can technically read the backups - like with any hosted backup service.
- There's no password to lose. Keeping the bot key safe is the job of whoever runs the bot.
- Not encrypted (visible to the server's admins): the backup ID, server ID and name, date, creator, the counts shown in
/backup listand the note. - The undo copy and transfer codes are stored the same way - the undo copy encrypted with a key of its own, transfer codes only as a keyed hash.
- Older backups created with their own password (shown once) keep it: they're still encrypted with a key derived from that password (PBKDF2-HMAC-SHA256, 600,000 iterations), and loading them asks for it.
Who may do what#
/backupis limited to administrators by default. Owners can change this in the server's integration settings.- Load, repair, undo, delete, transfer codes and switching automatic backups are owner-only. The limit of five manual backups is shared by all admins of a server - an admin could push out older manual backups by creating new ones, but not the automatic ones.
/backup deleteonly works for backups of the same server. - A backup can only be loaded onto another server with a transfer code from the owner of its own server - valid for 24 hours and one load.
- Once the bot has left a server for 7 days, all its backups are deleted - the data doesn't stay around for servers that no longer use the bot.
Bot permissions#
| Permission | Needed for |
|---|---|
| Administrator | Loading, repairing, undoing (checked before anything happens) |
| View Channel + Read History | Backing up messages of a channel |
| Ban Members | Backing up bans |
| Manage Server | Backing up AutoMod rules |
| Highest role position | Deleting, recreating and assigning all roles |
Ventura