3 ms·
Well, all of your contact information is sent as a hash to the Secret servers. I'm not an expert on cryptography, but I think the idea is that if you send your
by Pwntastic 12y ago
Well, all of your contact information is sent as a hash to the Secret servers. I'm not an expert on cryptography, but I think the idea is that if you send your information hashed, and all of your contacts hashed, and then all of your contacts send their info hashed, you only have to find out where the hashes match up and you won't actually need to know what the actual contact information is (the phone, email, whatever).
Everything sent over the wire to their apis is encrypted, but using an easily reversible fashion. The encryption key is a combination of a static salt and the user's session id. The session id is also sent to the api as an http header, so it's pretty easy to decrypt that anyway.
n.b. I wrote the windows phone app