|
|
|
|
|
by maxtaco
4466 days ago
|
|
We agree this is a problem, all of those who try to access their private key during the compromise would be in trouble. Those who stayed offline would be safe. BTW, this argument does not extend to the CLI or other uncompromised clients. People who sync their private keys across devices with the CLI are unaffected. |
|
If my understanding is correct, my question is: What is the reason for this difference in security for the two use cases, and isn't there some way to provide web access without reducing security? What about browser add-ons? Client certificates?