You are viewing a single comment's thread from:

RE: Hive core developer meeting #20

in #hive3 years ago

Did they say they would get rid of the master password?

It looks like this is something where front ends cooperation is expected as well. From the summary:

Then the discussion went on the master password which can be used to derive all the other keys, which is obviously an even bigger security risk. We are thinking of just removing the capacity from libraries to generate keys from a master password so that front ends won't feel enclined to offer a "login with a master password" feature. But there are UX tradeoff where now the user has to juggle with multiple keys, although that's less relevant now that we have great key management systems in place like keychain.