Hacker News new | ask | show | jobs
by rakoo 4388 days ago
We don't have a problem with symmetric encryption. We have a problem with the key being stored on your servers, effectively nullifying encryption.

Now, I'm not saying it's an easy problem; kudos to you for tackling it. It's just that

- if you have the keys to the payload

- if you don't provide open-source client code

then no one can honestly trust your service. Don't forget that what you're primarily doing with is trust.