3 ms·
You're really conflating issues. Yes, Store the Passphrase-protected private key on your server. No, do not send my passphrase to your server for a restore. Yes
by CodeWriter23 9y ago
You're really conflating issues. Yes, Store the Passphrase-protected private key on your server. No, do not send my passphrase to your server for a restore. Yes, send the private key to my client. No, do not decrypt my data server side. Yes decrypt it client side after I enter my passphrase into my client. No, don't transmit my passphrase anywhere at all.
By arguing the passphrase should be sent to BB servers, you're unnecessarily violating two fundamental principles of security, least access and least privilege.