Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

They recommend you to upload your _private_ key to their servers though! (Ok, encrypted with scrypt... but still...) ... a very bad thing to recommend users to do.


It's optional and encrypted, for most users it's the right choice. If you think of security as a spectrum - on one side you have protecting against dragnet collection and on the other you have protection from targeted attacks. Too often security discussions only talk about perfect security and while that is important, in the general case I think this is a good thing for most people.


I mostly agree (and my key never leaves my computer, though I've been considering sticking something in a safety deposit box), but I'm not entirely unsympathetic to the desire to offer more functionality. Is there a good solution involving delegation and short-lived keys?


Agreed, but this is all part of the core usability problem: it's too hard for users to reliably not lose their keys, and it's too hard to safely access them from all the places they're needed.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: