ParentFull threadsli·If the key is just in the URL, what's stopping them from simply obtaining the key out of their access logs and decrypting whatever they want?View on HN