agree, red flag.
it's easy to secure it by having the company NOT hold any valuable data:
Use the data (face) on the phone to generate a reproducible random hash, use that as a seed to generate private key.
No need to store anything on a server ever.
twetch#3667 6.5y
What the chain says
- Block
- 629 624
- Time
- 2020-04-07T13:24:33Z
- Signer
- 19nTUyw97xhqL7eVJzmAJT2RbTvbW84gwv
- App
- twetch
- Type
- post
- Content type
- text/plain
- Name in tx
- twetch#561
Fields the transaction did not carry are omitted. Open the payload to see the bytes as stored.
Signed by
19nTUyw97xhqL7eVJzmAJT2RbTvbW84gwv Verified