4 ms·
I am typically one of the opinion that if you are doing crypto in javascript you are doing it wrong. Talks like http://rdist.root.org/2009/08/06/google-tech-ta
by tdmackey 17y ago
I am typically one of the opinion that if you are doing crypto in javascript you are doing it wrong.
Talks like
http://rdist.root.org/2009/08/06/google-tech-talk-on-common-crypto-flaws/ http://rdist.root.org/2009/08/06/google-tech-talk-on-common-... provide insight and let us not forget http://chargen.matasano.com/chargen/2006/4/28/oh-meebo.html http://chargen.matasano.com/chargen/2006/4/28/oh-meebo.html
Besides it is very difficult to have javascript return sutiably random numbers cross platform. If you need to encrypt browser traffic use ssl instead of some half-assed pseudo-secure javascript mess.
Sorry JSCrypto team, while your implementation is awesome and all, you are doing it wrong.
- woadwarrior01 17y agoWhile your caveat is true for people using this on the client side, what about people using javascript on the server side ? Though its probably best to use C wrappers to established crypto libraries on the server side, we shouldn't underestimate the ease of use which comes with using pure javascript libraries.
- tptacek 17y agoThere's nothing intrinsically unsafe about serverside Javascript crypto, but there's something practically unsafe about directly using AES anywhere. In the meantime, serverside Javascript as a rule has access to better native AES code. The browser definitely seems like the motivating use case here.