Hacker News new | ask | show | jobs
by elliewithcolor 841 days ago
Out of interest: why did you implement SRP and did not wait till OPAQUE is finished? And do you plan to implement OPAQUE in the future (tm)?
1 comments

Before implementing SRP, our authentication flow relied on email verification.

The general inconvenience of waiting for emails aside, this flow also had the potential to lock out customers who were using Ente Auth to store their email's 2FA credentials. So it was important that we fixed this.

Once OPAQUE becomes more mainstream, we will very likely adopt it.