5 ms·
Sounds interesting. What does tptacek say?
by apike 16y ago
Sounds interesting. What does tptacek say?
- siculars 16y agoThe main page does talk specifically about issues with running crypto in the browser: "Unforunately, this is not as great as in desktop applications because it is not feasible to completely protect against code injection, malicious servers and side-channel attacks." Nevertheless, I wonder what tptacek thinks about the implementation.
- ErrantX 16y agoWhat it should probably say is: "Unforunately, this should not be considered a secure alternative to desktop applications because it is not feasible at all to protect against code injection, malicious servers and side-channel attacks." The unfortunate thing is that however cleverly you mess around with Javascript code the current (browser) implementations break all security. tptacek is a little "zealous" about this topic in particular :P (and I actually do see a use for JS crypto as a method of obfuscation, rather than security) but he is right.
- tlrobinson 16y agoOf course desktop apps are usually downloaded from the web these days so they're also vulnerable to many of the same problems...
- count 16y agoI bet tptacek is wondering why he needs to keep saying the same thing over and over again :)
- rubyrescue 16y agoif you are typing in the letters S-T-A-N-F-O-R-D while doing crypt... oh wait...
- tptacek 16y agoIt's a really good implementation built by really smart people who are making a calamitous mistake with how they market their work, because, like Colin Percival on Hacker News, they don't fully appreciate how badly generalist developers will abuse this code. "Oh boy!", they don't realize those developers will think, "now I don't have to buy an SSL certificate!".
- michaelfairley 16y agoWas that jab at Colin really necessary?
- tptacek 16y agoPresumably you were downmodded for suggesting that comparing Colin Percival to Dan Boneh is a "jab". I've modded you back up, but, now you know.