4 ms·
I cannot try anything before entering my CC number (and paying, no free month or anything), nor finding any detailed information about the setup (apart from 'pu
by bwblabs 11y ago
I cannot try anything before entering my CC number (and paying, no free month or anything), nor finding any detailed information about the setup (apart from 'public/private key client side JS'). But the site/server/data center security probably does matter if the JS is hosted at their site / servers.
Edit:
See link below: https://privateforms.net/embed/rNKlzL https://privateforms.net/embed/rNKlzL
So you get jquery, moment, bootstrap + datatimepicker, kbpgp and a few lines of glue to use kbpgp to send and XMLHttpRequest, basically:
kbpgp.KeyManager.import_from_armored_pgp({
armored: '-----BEGIN PGP PUBLIC KEY BLOCK-----\n' +
/* key */
'-----END PGP PUBLIC KEY BLOCK-----'},
function(err, keyManager) {
kbpgp.box({msg: '**form=data**', encrypt_for: keyManager},
function(err, encryptedString, encryptedBuffer) {
//send result;
}
);
});
- locacorten 11y agoI like your answer because you're describing a new threat model: an adversary tries to subvert the encryption process. Their service does not protect against such a threat. Securing the data center is the least of your worries for such an attacker. I'd detail additional attacks that all subvert the encryption process: 1. Compromise the site's private SSL certificate. This allows the possibility of MITM attacks. There is some evidence that NSA is already mounting such attacks on the Internet. 2. Malware on the client-side. A compromised browser, or a compromised OS. 3. The US government mandating that NSA installs hidden firmware on all data center servers. I argue that strong semantics are extremely important when building secure services. I thought their service offers one such semantic: client-side form data encryption. They do not offer JS code integrity or any guarantees about the client-side encryption not being subverted. By telling people about datacenter security and then calling it a "a detail that some people who are security-conscious might care about" or "data center security probably does matter", you continue to raise the fog of confusion in people's minds. Instead, the FAQ could educate the users and separate client-side encryption (which is what the service offers) from client-side code integrity (which the service does not offer).
- MichaelGG 11y agoThere is no such thing as usable encryption without integrity (authentication). Client side crypto here changes rather little.
- sjs382 11y agoI've implemented a 14 day trial period, for users to test the service before staying with us.