Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Making it password dependent means that they have to decrypt/encrypt when you change password.

And also that you losing your password is apocalyptically bad.



There are some ways around that, but basically you're correct. (For example, you could store the user key, or an additional randomly-generated password, persistently on client machines, so that you can usually recover from password loss; and you could use a tree of session keys to minimize the amount you have to re-encrypt. But basically you're right.)

It's understandable that they chose a less-secure system design. It's not understandable that they chose to lie to their customers about it.


Oh, I totally agree. Honesty up-front would have been a much, much better policy.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: