Comment by winstonwinston
3 days ago
The sane way for encryption keys stored in hardware (secure enclave or tpm like) is to onboard user when the key is not derived from user password. Just like they do for FDE to export a recovery key and then you can adjust your expectations when you know (been told) whats going on.
No comments yet
Contribute on Hacker News ↗