82 karma · joined March 27, 2012
For this we're going to have to rely on SSL but the server does check that the messages sent by itself and by the browser plugin are not modified in transit and will prevent login if they were.
* What if someone gets your private keys, and gets your password with a keylogger? This looks like "game over."
Well the encryption key is derived using random salts that are in the database so a keylogger alone won't work. Of course it would be trivial to create software to steal the salts as well but if you're computer is infected with malware TrustAuth is no worse than passwords.
2. I plan on adding in an import/export feature for the next release.
3. This should be more secure than passwords because the only information that the server gets is your public key, which of course is assumed to be public knowledge. No more wondering if the website you're using is properly storing passwords.
Thanks for the questions.