Hacker News new | ask | show | jobs
by viraptor 3690 days ago
After thinking through the initial "this is terrible" reaction, I actually don't mind what they're doing. Even though if there was an equivalent solution that was based on open source I'd definitely choose it over YK 4.

I also don't see anything that would really prevent them from just releasing the source they're using, even if we can't realistically do anything useful with it. The whole point of those systems is that it's secure via algorithms and hardware silos - releasing their sources shouldn't change anything.

But in practice it doesn't really matter that much - as long as they use standard interfaces and replace your key for free if someone finds a vulnerability, I'm (cautiously) fine with their new position. I think a big part of the issue is that they did something better before, but if they started with the current design, people wouldn't really complain about it that much.