You are viewing a single comment's thread from:

RE: Leak -- Compromised MEMO key successfully protected

in HiveDevs3 years ago (edited)

No, that doesn't make sense.
There's no forward secrecy, once leaked, it's over.
With the active key (where consequences can be much worse as it controls finances) it is ironically much simpler, because first you could tell looking at account history if there were funds movements between leak and the moment key was changed.
In case of memo key you just know that it happened and you can do nothing but just let owner know.
It doesn't protect them, it just inform them (if successful at all) about the fact.

Sort:  

I see what you mean now. Their past encrypted messages are leaked forever, that's a good point.

  1. For memo keys I'll change the post title to "Compromised MEMO key detected"
  2. I'll add some text in the post that says something like "review for sensitive info all the encrypted messages that you sent with the compromised memo key. Now they are all public forever.."
  3. And following your thinking, it's probably better to not disclose their full account name in the "monthly" report.