Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> I read the paper when it was published, and wasn't great then and it's definitely not great now.

Would you mind elaborating on this?



It's really simple. It just doesn't consider anything unexpected happening.

Compromised algorithms are unlikely. But not impossible. Quantum computing enabling brute force attacks is unlikely in the immediate future, but not impossible. Certificate pinning compromise during transport is not implausible for state actors.

And in those scenarios and others, having the vault stored remotely on someone else's machines is inherently less secure than not.

The assumptions made in the paper are clumsy.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: