logoalt Hacker News

dannywyesterday at 5:15 PM1 replyview on HN

The provider has the hidden text anyway; this isn’t customer managed encryption.


Replies

yubblegumyesterday at 6:23 PM

Sure, but if each session has a unique key then these need to be managed and stored and unauthorized access to these leaves tracks. So all that had to be 'compromised' is a single universally applicable key. Again, the question stands: session based encryption can be scalable and efficient. Why aren't they using it?

show 1 reply