3 ms·
You can't generalise MITM and injection attacks to "Javascript crypto is bad". There's an idea floating around called "host proof hosting" - or in the Clipperz
by cortesi 17y ago
You can't generalise MITM and injection attacks to "Javascript crypto is bad". There's an idea floating around called "host proof hosting" - or in the Clipperz parlance, "zero-knowledge applications" - that I think could be potentially very important in future, and that relies entirely on Javascript crypto. The only problem is that I haven't seen it done right yet - every application I've looked at that claims to implement this paradigm has some enormous, glaring shortcoming.
I'm working on an epic tldr; blog post and an associated project release related to this - keep an eye out for it next week.
- colonelxc 17y agoYou're right about that, I certainly over generalized the issue. I should have just stuck with "javascript crypto shouldn't be used in place of TLS." The host proof hosting stuff is pretty interesting. Some people implement something similar when using dropbox, by encrypting the files before they are synced. A disadvantage of this method (other than being cumbersome), is that you lose the bandwidth savings of Dropbox's deltas.