Hacker News new | ask | show | jobs
by AlexandrB 696 days ago
> The service provider has every right in the world to demand the user prove that they are securely storing the credential in a way that can't be extracted.

Wait, really? Does this work both ways? Do I get to demand that the service provider store the data it collects about me in a way that can't be extracted? Oh, apparently not[1]...

[1] https://www.technologyreview.com/2023/07/17/1076365/how-tech...