by andyshora on 3/30/12, 12:22 PM with 15 comments
by mckoss on 3/30/12, 2:00 PM
So, rather than allay fears about his service, I'm left feeling more skeptical about their claims.
I would love hear from people more versed in cryptographic key exchange protocols as to the basis for their claims.
And, seriously, a Michael Scott protocol?
by rdl on 4/1/12, 2:50 AM
There isn't anything inherently browser based about this.
I'm not a huge fan of browser based security (I know just enough appsec to be terrified).
If they had an API, it would be fun to do a secure mobile client for it (I trust iOS security way more than PC browsers..). There is less point when you have a client (just as easy to build some kind of key server with locally stored keys), but being able to send messages to future users is a nice trick.)
It looks like an interesting use of HSMs. I'm curious if they do real crypto in the HSM or just use it to protect a bootable VM. If it is just a VM, there are a lot more attacks possible.
by emily37 on 3/30/12, 3:31 PM