Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Hypothesis 1: He wants to give low profile users, the kind that use it for mundane things (because why not use cryptography?) the chance to recover their mail at the cost of a privacy leak. In his hurry he forgot the minor detail of PFS. Fetching their email now is not for the paranoid anyway. The alphabets have root. Hypothesis 2: The alphabets set it up as a trap and simply forgot to turn on PFS like before.

Interestingly, in both scenarios the activity will be very logged and the alphabets will get all your data, but absence of PFS is unrelated to this.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: