Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

That doesn't work, Dropbox/your favourite TLA will just wait for you to supply the password and then save the key. Trading off the inconveniences of good crypto (e.g. no web interface) for that little security isn't worth it.


The system suggested by shin_lao does not require that the password be passed back to Dropbox to retrieve the key.


If Dropbox wants to serve the files to a standard browser, it does need the decryption key. If I misunderstood and shin_loa wants to drop the web interface, why "key escrow" - why not directly derive the key from the passphrase?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: