Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

And just to be clear, the big part he's missing is about web apps. Whisper Systems is very clear that they're not doing a web version:

https://github.com/WhisperSystems/Signal-Desktop/issues/723

If they did, they would be the one holding the keys, not the user. The proposed solution also ignores the new-device case. If you install Twitter on your new phone, log in, and look at your DMs,you expect the whole history to be there. But if messages are encrypted for each device at time of transmission, then the new phone starts blank.



Don't browsers have a certificate store that can be used to store private keys?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: