3 ms·
Because if you serve the library responsible for the encryption from the server, an attacker can perform a man in the middle attack and change that library. Thi
by remy_ 10y ago
Because if you serve the library responsible for the encryption from the server, an attacker can perform a man in the middle attack and change that library. This will change when browsers will start implementing the web crypto api. https://www.w3.org/TR/WebCryptoAPI/ https://www.w3.org/TR/WebCryptoAPI/
- eganist 10y agoThe concern is less MITM and more a compromise of the server, but close enough. Check my parallel response to Omnipresent's comment.
- remy_ 10y agoFair enough, whatever is the easiest for the attacker :). I'm checking Cyph and its "Trust On First Use" concept. Very interesting.
- eganist 10y agoIf you're dropping by defcon, you should catch the talk. There'll be very little focus on this mechanism specifically since we want to share a bunch of things people can actually freely use (and this isn't one of them), but you can catch Ryan afterwards and spark a conversation to find out more.