You are viewing a single comment's thread from:

RE: HiveSigner is INSECURE? - discussion and deep dive

in HiveDevslast month

Any site that asks for a 'master key' seems dodgy to me. They shouldn't need that level of access.

Key security is not an easy problem to solve and so we have to trust the developers for such tools. I would hope that anyone with real concerns can feel free to speak out, but obviously should go to the devs first if there is an immediate risk.

Sort:  

This is legacy software, as you say (and @techcoderx mentioned) these are tricky issues.

I never made a post before, I just ignored this legacy login method (which was more secure in its day than copy pasting keys).

But I felt compelled to look into it and make a post when I felt mistreated for not drinking the koolaid and exclaiming that it was the most safe and secure app in the world, which it is not.