Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Are the keys not already kept on their own infra?


No, private keys don’t leave user’s devices. This is the case in all such products.

But with a malicious update, they could ship them to their infra, targeting some users. The product then becomes malware!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: