Skip to content

Comment on NoPlainText: One time, browser-encrypted messagingparent

Comments

Moreover, if the server stores enough information for a recipient to read the message, then the server effectively stores the message.

Hmm, oh, I think the stuff after the hash is the decryption key, and we're assuming the server throws it away.

We still require a trusted third party here.

The HTML anchor never reaches the server in the request, it's for local use only. Of course, malicious JS on the page can always send it anywhere.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.