3 ms·
I'm still trying to figure this out but isn't it sending the ECDH of the private key which would be much longer then what the average user is going to use as a
by d1plo1d 11y ago
I'm still trying to figure this out but isn't it sending the ECDH of the private key which would be much longer then what the average user is going to use as a password (eg. I don't know, 1024 bit or something) and therefore more secure then sending a hashed password?
Edit: And then you (maybe?) use your password to encrypt the private key locally.. maybe? That's a total guess. That's what I'd do :P