logoalt Hacker News

HoyaSaxayesterday at 7:24 PM0 repliesview on HN

I can’t believe they don’t validate a decrypted signature belongs to the user or use a unique encryption key per user/session.