16 ms·
So one thing, it mentions that it is JS dependence free. How are you encrypting the files client side then? If you are encrypting the files server side, then
by uncled1023 8y ago
So one thing, it mentions that it is JS dependence free. How are you encrypting the files client side then?
If you are encrypting the files server side, then that is NOT E2E encryption.
- jesseb 8y agoThere are JavaScript files in the GitHub repository, so I'm going to assume they mean third-party dependencies, but some more clarification would be nice. There is a file called cipher.js with encrypt and decrypt functions https://github.com/countable-web/cryptsend/blob/develop/public/js/cipher.js https://github.com/countable-web/cryptsend/blob/develop/publ...
- uncled1023 8y agoYea, and I just noticed it downloading a bunch when visiting the page. So it's probably safe to assume they mean 3rd Party.
- ech085 8y agoConfirmed. The intent is anyone can audit our whole codebase in one GitHub repo for vulnerabilities and not scripts spread across many CDNS and projects which may change over time.
- JepZ 8y agoI wonder what JS dependencies FTP has...
- ech085 8y agoGood catch, thanks! We'll fix that.