Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

you can. however, i hope they don't store it unencrypted - it's a very bad security practice for many reasons. assuming they store it encrypted with a temporary session key, the session key will necessarily be on the server. honestly, storing it on the server in a session storage is not a big deal. my original points are that a) web security is hard b) web e2ee is sort of hype on practice


From what I understand they store it unencrypted on the web, but in the device's keychain when using the Desktop application.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: