5 ms·
Well, you still have to trust them not to ship a website update where the client side scripts would leak your decrypted private key :) To be fair, you also hav
by floatboth 6y ago
Well, you still have to trust them not to ship a website update where the client side scripts would leak your decrypted private key :)
To be fair, you also have to trust native apps and browser extensions the same way. But with websites, the risk of a sudden and targeted (not noticed by the general public) update is much greater!
- namibj 6y agoWhich is why they push you towards not using the website, and also explain how they (through some steps) put their application version's hashes into the bitcoin blockchain. And the client is open source, which iirc includes being built by distribution's maintainers/build servers instead of Keybase.io.