Skip to content

One keypair per domain? #10

@rekado

Description

@rekado

Currently, only one keypair is stored per profile. Any page could trigger window.mozCipher.pk.generateKeyPair and thus overwrite the stored key, meaning that the user will lose access to whatever encrypted data had previously been encrypted under the user's public key.

Does it make sense to instead store one keypair for each domain, thereby restricting write access to the keypair?

(How does the Web Crypto API intend to deal with this?)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions