What happened on hive-roller was a bad security hotpatch that reset accounts to a valid state of security.. Allowing a user to stack up withdrawals and log in and out in order to bypass security. They never breached the server nor got into data, it was merely a function of security being nullified by a hotpatch I'd done prior. :/
I don't deal data from my house and once a proper AES encryption method for on chain storage that can't be cracked easy is formulated everything moves that way implementation wise..
Right now as it sits using a hybrid AES-256 and PGP encryption for keys.
An alternative method I've thought up is to heavily encrypt the new set of keys and then provide the user with that at the start of the loan.. Then give them the password once complete.
The goal is to eventually have not human access to keys whatsoever, and like you said, decentralize everything.
Your doubt kind of took me off guard to be honest. Tis healthy to have doubts though I guess, Thanks for raising your concerns man. I'm literally building the infrustructure to make Hive.Loans possible with HSC.. I'd appreciate it if you not FUD and slander my projects and cast libel at me.. :/