5 ms·
No -- we treat every communication channel as untrusted. All communication between the phone and computer is encrypted with session keys established when you pa
by 4kevinking 9y ago
No -- we treat every communication channel as untrusted. All communication between the phone and computer is encrypted with session keys established when you pair by scanning the QR code in the terminal. Check out our architecture post for more details: https://blog.krypt.co/the-kryptonite-architecture-a385e7aaa336 https://blog.krypt.co/the-kryptonite-architecture-a385e7aaa3...
- akerl_ 9y agoIf I'm reading this, the answer is actually ~Yes? The requests pass via SQS/SNS run by Kryptonite, or via Bluetooth not run by kryptonite?
- 4kevinking 9y agoIndeed, (encrypted) requests pass through SQS/SNS with credentials owned by us. We can see the amount of traffic, but not any of its contents or who sent it.
- henryfjordan 9y agoFollow-up: Since it seems all the code is open-source, is it possible for me to run this service on my own server (or at least in my own AWS setup)?
- bobwaycott 9y agoThe lack of a license leaves this very unclear.
- elahd 9y agoGitHub's user agreement allows for the free use of any code posted in a public repo.
- akent 9y agoNo, it doesn't. Standard copyright applies if there is no licence. GitHub user agreement allows other users to view and make copies of your content on github but not for "free use" in general. https://help.github.com/articles/github-terms-of-service/#5-license-grant-to-other-users https://help.github.com/articles/github-terms-of-service/#5-...
- newman314 9y agoIs there an option to configure this to run across only BT? This would mean that the phone needs to be physically close in order to accomplish auth and I would think that's a good requirement based the premise of this app.