3 ms·
Yes, I hope they hash the secrets (and I guess someone could monitor the network traffic from the client to tell). Also, if someone did have the master list of
by dotBen 13y ago
Yes, I hope they hash the secrets (and I guess someone could monitor the network traffic from the client to tell).
Also, if someone did have the master list of hashed secrets, they might still be able to manipulate their own client to send the hashed secret back to the server and gain access.
Being closed source, it's hard to know what the potential vectors are (granted, Dropbox is also closed source).
- akama 13y agoYou are correct that it's hard to judge security when the application is closed source. However the in the model we are suggesting, having the hashed secret would not be sufficient to get access to the files. Although you could use it to find client's IP addresses you would not be able to connect with it. The reason being that the secret key would be the base of any encryption between clients.