Hacker News new | ask | show | jobs
by cbsmith 2664 days ago
Yeah, you're missing the security model.

The point is to have the decryption done on a system that is isolated from the production environment (and is consequently isolated from security compromises).