Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's actually not a bug -- it's because the client never sends the password to the server. (It decrypts your wallet locally.)


It makes sense. It looks like they've just added this message: "If you refresh you will be automatically logged out since it isn't safe to keep your password on disk."


The funny thing to this is, that keeping the password on disk isn't proclaimed safe but sending each user the recovery code over plain text mail withouth encryption is...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: