3 ms·
When importing the passwords into a new devices you’re required to enter the device password of whatever device created the password initially. Still no proof
by mabedan 2y ago
When importing the passwords into a new devices you’re required to enter the device password of whatever device created the password initially.
Still no proof that there’s no back door, but as far as the system on the surface goes, it does make sense.
- kevincox 2y agoOh, I didn't notice that. I guess this is using their hosted HSMs to do the PIN check? Otherwise it would be trivial to brute force. But if they are using hosted then I think it can be considered a proper E2EE system.