4 ms·
It's a simple static site with no server involved. Everything happens client side. You could turn off your internet while you're using it if you wanted to make
by aith 6y ago
It's a simple static site with no server involved. Everything happens client side. You could turn off your internet while you're using it if you wanted to make sure no data is exposed.
- dzhiurgis 6y agoWould a service worker running in background be able to upload your sensitive data once you are back online?
- KingMachiavelli 6y agoTrue, but it's only safe if you do that. You have to either inspect the code every time you use the site or run it locally. Until subresource integrity [1] becomes widely used & the capability to 'pin' a given script to a specific version, web applications can not be used without at least trusting the owner of the domain. A better example is Protonmail, a secure email service. It has a nice web client and there is an 3rd party desktop/electron version of the same size called Electronmail. While both essentially run identical code, the electron version is more secure because even Protonmail insert a backdoor for a single or # of users. They would have to at least publish the backdoor in the vanilla code at which point, the maintainers of Electronmail will probably raise the alarm. [1] https://developer.mozilla.org/en-US/docs/Web/Security/Subresource_Integrity https://developer.mozilla.org/en-US/docs/Web/Security/Subres...
- rkagerer 6y agoWrite a little piece of open-source client software to take a hash of the source code. Check the hash every time you use it. Spread the tool around to a community of people who review every time the hash changes and publish (separately) a history of attested hashes.
- t-writescode 6y agoOr, you could download the repository, validate it once for yourself and then use it repeatedly. It is open source, after all.
- vagab0nd 6y agoFor linux users you can "turn off" internet for a single program: https://news.ycombinator.com/item?id=21146655 https://news.ycombinator.com/item?id=21146655
- rkeene2 6y agoI actually wrote an even better way to do this, since my build system drops network access after downloading SHA-256 validated source (to ensure that source can't go out and fetch more things during build): https://chiselapp.com/user/rkeene/repository/bash-drop-network-access/index https://chiselapp.com/user/rkeene/repository/bash-drop-netwo...
- heavyset_go 6y agoA bad actor could selectively serve a different version to those they want to target.
- abathur 6y agoThere's no way to obtain and execute source code that you didn't write and hand-compile for which this risk doesn't exist. (And it applies in its own sense to books, paintings, phone calls from mom, letters from an old mentor, DVDs, rental cars, ...)
- heavyset_go 6y agoDownload, verify keys and signatures. You could run a checksum or even read the code yourself depending on how paranoid you are. Otherwise, you're just hoping mycrimepics.net/dontsnitch wasn't subpoenaed between your last visit and now.