4 ms·
The reason Javascript won't do the trick is that in order to send the correct Javascript, the server needs to have all the information necessary to decrypt all
by stevejohnson 16y ago
The reason Javascript won't do the trick is that in order to send the correct Javascript, the server needs to have all the information necessary to decrypt all the content anyway. So there's no point in the encryption at all, because the information will pass through the server unencrypted at some stage and can be captured.
If this were implemented as a browser feature or plugin, machines with the user's key information installed would be the only devices capable of decrypting the content sent by the server.
- stcredzero 16y agoMy point is also that there's (almost) no point in the encryption at all. If Diaspora is going to be P2P, then any compromised node can hijack the data. The only point of encryption would be to protect information enroute. Once information gets to a node, you either need trust, white box encryption, or hardware based DRM.