Hacker News new | ask | show | jobs
by acveilleux 4388 days ago
The login protocol require sending a hash of the key used to decrypt the rsa key bundle stored server-side. I hope they implemented a constant time compare for that hash so that verification can't be used to work out key...