Hacker News new | ask | show | jobs
by Ralz 4389 days ago
Isn't keeping the key not on the client more secure. If the encrypted data is on the client then the key would have to be on the client at some point to decrypt it. If my phone is jailbroken it wouldn't be too hard to extract the key and depending on the security of the app it may be likely that this key is used for every client.