I recently pointed out to a friend from a friend who said that Google is moving in the direction of secrecy. From what I understand, the essence of hidden secrecy seems to be that private keys are not stored in persistent storage.
I have various doubts about how something like this can be implemented.
- What if the server drops without warning - do I need to rebuild the key pairs? Do I need to publish the key again to create another certificate?
- Can someone please point me to the / pdf messages where the implementation of something like this is described. Recommended reading resources?
- Do you know anyone who has implemented direct secrecy? Have you tried something like this in your workplace?
Thank!
user277465
source
share