Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm very curious as well because my very limited understanding tells me the answer is nothing. The relay hides your identity. Your phone checks the attestations so it won't send your data to servers not running the published software which ensures encryption keys are ephemeral. Once your session is done, the keys are deleted.

Law enforcement would need to seize the right server among millions while it's processing your request and perform an attack on it to get the keys before they're gone.

My next question is what happens if/when the attestation keys are stolen.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: