4 ms·
Javascript and cryptography are two words that should never be used together. I can't believe people think this provides some decent form of security. Instead o
by tdmackey 17y ago
Javascript and cryptography are two words that should never be used together. I can't believe people think this provides some decent form of security.
Instead of worrying about the security of some javascript crypto implementation you should be more focused on wtf kind of problem this actually solves without introducing a slew of new weaknesses. TLS/SSL provides end to end encryption and doing any random crypto in javascript doesn't provide anything on top of that. And if you aren't using TLS/SSL then the code is still coming from your server in plaintext. If it is sent in plaintext then it can be replaced by an attacker therefore requiring you to send it over https and since you are already doing that why bother with javascript crypto when you can just send the data over the secure connection you already made?