Hacker News new | ask | show | jobs
by brownbat 5165 days ago
Moreover, if the server stores enough information for a recipient to read the message, then the server effectively stores the message.
1 comments

Hmm, oh, I think the stuff after the hash is the decryption key, and we're assuming the server throws it away.

We still require a trusted third party here.

The HTML anchor never reaches the server in the request, it's for local use only. Of course, malicious JS on the page can always send it anywhere.