Hacker News new | ask | show | jobs
by spacemanmatt 4158 days ago
It's of no use when it's encrypted.

Oh, right, decrypt it real quick in the app, right? How will you protect that decryption key?

1 comments

Decryption can require several servers to participate rather than one - don't allow for a privileged user on one server to have an easy path way to access and escalate on another server.

From the way it looks, the security precautions they are failing at are so trivial that most developers probably have more secure personal servers / computers.