logoalt Hacker News

t-writescodelast Friday at 6:44 PM1 replyview on HN

They give you a key and only if you have a higher tier account. The act of doing that requires that there is a step in the process where they know you’re requesting a key and who you are. They could bind them in the backend if they wanted, before giving it to you.

You’re still trusting them. Not to mention they could round them all up by IP or browser fingerprinting.

There is still some level of trust.

I happen to trust them enough for that; but it is still trust.


Replies

doogliuslast Friday at 7:16 PM

I am not an expert in the underlying cryptography, but the claim is indeed that the cryptographic approach makes it impossible for them to link the key to the queries in the backend.

show 1 reply