4 ms·
That is a very interesting claim on their part considering that they hold the private PGP keys used by their service. I'll have to figure out what they mean by
by bitdizzy 6y ago
That is a very interesting claim on their part considering that they hold the private PGP keys used by their service. I'll have to figure out what they mean by this.
Edit: Ok I see. They store the PGP keys encrypted with your password. Like you said, they could just as well inject javascript to phish your password from your session.
But this does seem to mean that if one uses their API directly it would be possible to securely use their service. Thanks for the heads up. There is a third party open source bridge that reverse engineers their API. I think I will look into it to see how authentication is done.
https://github.com/emersion/hydroxide https://github.com/emersion/hydroxide