8 ms·
I think the disconnect here is, many of us can't imagine offering something with known technical security issues such as browser side JS encryption, and brandin
by jmccree 13y ago
I think the disconnect here is, many of us can't imagine offering something with known technical security issues such as browser side JS encryption, and branding that "secure". Much less with all the unknown legal, operational, and techical security issues that may arise later in a project like this. As well, from what I read this project transfers your (encrypted with only a passphrase) private key over the internet, where it will be caught in the dragnet for decryption later.
I find it far more dangerous for someone to think they're secure against government level threats, than to know they're not. And if you're not worried about government level threats, gmail with MFA and pinned chrome certs is likely safer than this project. Of course, this is all just my humble opinion...