Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It appears that they do take certain security measures: http://www.trov.com/security/

Though, I'm not sure how I feel about some of their caveats, most notably 1 and 2 below, which correspond to exceptions about disclosing your data to third parties [1] and deleting your data [2]:

    [1] Unless legally required to comply under court order.

    [2] Unless compelled by a legal, court, judicial or administrative order to retain it.

    [3] [AES-256-CBC](http://en.wikipedia.org/wiki/Advanced_Encryption_Standard)
Number [3] above is in regards to the encryption standard they use for your data. Unfortunately, I can't comment on how good it is compared to other options (XTS, OCB), but it seems like [1] and [2] imply that they can get access to your data, so I think more explanation with regards to how they manage passwords / encryption keys is necessary to really judge the system.


If they can be compelled to decrypt your data, their encryption system is probably worthless.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: