TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

How can PrivateSky not see your data?

30 点作者 andyshora大约 13 年前

3 条评论

mckoss大约 13 年前
This is an example where a short answer is better than a long answer. There is so much detail provided by the CEO in his explanation, that it is very difficult to understand the outline of the protocol and structure of the system. Security does not derive from complexity, but rather a careful analysis of the potential attacks and their difficulty.<p>So, rather than allay fears about his service, I'm left feeling more skeptical about their claims.<p>I would love hear from people more versed in cryptographic key exchange protocols as to the basis for their claims.<p><i>And, seriously, a Michael Scott protocol?</i>
评论 #3775987 未加载
评论 #3776383 未加载
评论 #3776256 未加载
评论 #3776038 未加载
rdl大约 13 年前
I think the crypto behind this is valid; weaknesses would be in implementation or in bypassing it.<p>There isn't anything inherently browser based about this.<p>I'm not a huge fan of browser based security (I know just enough appsec to be terrified).<p>If they had an API, it would be fun to do a secure mobile client for it (I trust iOS security way more than PC browsers..). There is less point when you have a client (just as easy to build some kind of key server with locally stored keys), but being able to send messages to future users is a nice trick.)<p>It looks like an interesting use of HSMs. I'm curious if they do real crypto in the HSM or just use it to protect a bootable VM. If it is just a VM, there are a lot more attacks possible.
评论 #3783455 未加载
emily37大约 13 年前
All these acronyms for a browser-based service? Even if you trust this company to have good intentions, it seems that the weakest link by far is the possibility of an XSS, a malicious extension, or a CA compromise. And of course the whole thing depends in multiple ways (verifying your identity, logging in if you clear localStorage, etc.) on the security of your inbox. Their crypto and protocol might be fine, but they should be more forthcoming about the many pieces of software that you are trusting when you use their service. I skimmed their whitepaper but didn't see any mention of the ways that they or someone else could in fact see your data.
评论 #3783466 未加载