Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>> storing a symmetrically encrypted OpenPGP keyring on the server

> now THAT is the way to do it!

Um, no. No, it absolutely is not.

See also: Hushmail.



One big difference with Hushmail is that they are a web app, so they can be (and have been) compelled by law enforcement to serve malicious code to certain users. Parley is a standalone desktop/mobile app, so it would be difficult for that scenario to occur. The passphrase is also PBKDF2'd on the client, so the server never sees it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: