4 ms·
Even with the brute protection provided by scrypt, it's very worrying that you can assume the encrypted private key will A) Be available to authorities via (sec
by jmccree 13y ago
Even with the brute protection provided by scrypt, it's very worrying that you can assume the encrypted private key will A) Be available to authorities via (secret) court order B) Captured and stored by NSA types. The security of the key could only be assumed to be as high as the weakest passphrase ever used by the user. With what we know about most user's password security (especially the type not already capable of using GPG, which would seem the target market of this) this seems like a very bad idea.
Why go through all the trouble of attempting strong client side crypto, only to store the private key secured only by a passphrase on the server?