logoalt Hacker News

barbazooyesterday at 3:54 PM1 replyview on HN

They likely wouldn’t rate limit themselves, rate limiting only applies when you access through their cute little enter your pin UI.


Replies

solenoid0937yesterday at 4:32 PM

The PIN is used when you're too lazy to set an alphanumeric pin or offload the backup to Apple/Google. Now sure, this is most people, but such are the foibles of E2EE - getting E2EE "right" (eg supporting account recovery) requires people to memorize a complex password.

The PIN interface is also an HSM on the backend. The HSM performs the rate limiting. So they'd need a backdoor'd HSM.

show 2 replies