<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security on Vlad Gorokhov</title><link>https://gorokhov.dev/tags/security/</link><description>Recent content in Security on Vlad Gorokhov</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 31 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://gorokhov.dev/tags/security/index.xml" rel="self" type="application/rss+xml"/><item><title>How a key transparency self-audit can verify the wrong identity</title><link>https://gorokhov.dev/posts/key-transparency-self-audit/</link><pubDate>Mon, 31 Aug 2026 00:00:00 +0000</pubDate><guid>https://gorokhov.dev/posts/key-transparency-self-audit/</guid><description>&lt;p&gt;An encrypted email can arrive in the right inbox after someone else has already read it.&lt;/p&gt;
&lt;p&gt;The cryptography is still doing its job. The mistake happens earlier, when the client receives the wrong public key.&lt;/p&gt;
&lt;p&gt;I am building &lt;a href="https://thelemail.com" target="_blank" rel="noopener noreferrer"&gt;Thelemail&lt;/a&gt;
, private email hosting for people and small teams using their own domains. Stored mail remains encrypted, and readable private-key material stays on each user&amp;rsquo;s device.&lt;/p&gt;
&lt;p&gt;Thelemail has to solve public-key distribution too. A sender needs the correct key for the intended recipient. Give the sender a different one and the message is encrypted correctly for the wrong person.&lt;/p&gt;</description></item></channel></rss>