|
|
|
|
|
by maxtaco
4466 days ago
|
|
k is derived from a password in this case, so capture of the password implies capture of k. We give people the option to store their encrypted secret keys on our server to make it easier to manage their key and sync it across their devices. |
|
Almost everyone who will use this for the first x years will be technically savvy - for example having heard of PGP. And as such they will have seen a hundred "secure" sites that try and keep passwords and keys on the server - do not associate yourself with that level of security obfuscation.
Cut some code out of your codebase, keep your marketing message small and tight - and offering to also sync keys across devices is not a tight message.