Hacker News new | ask | show | jobs
by ralfk 3498 days ago
Okay and how do you choose the key for the encryption? If it is the same for all users (which from what you said it kind of has to be?) you could just decrypt it?
1 comments

A hash of the email stored then compared to a hash of the email sent during reset
Exactly. This is the main idea behind Dikalo. Your private stuff belong to you. We are only interested in sending your messages. This is why you can use Dikalo without even siging up