4 ms·
> I'd add an anonymous option to the login Good idea. I'll check with Alain (the UI guy). > if it's non-encrypted or encrypted It's always encrypted (WebRTC
by jech 6y ago
> I'd add an anonymous option to the login
Good idea. I'll check with Alain (the UI guy).
> if it's non-encrypted or encrypted
It's always encrypted (WebRTC doesn't support plaintext communcation). If we ever add an option for end-to-end encryption, we'll add an indicator.
- pmaynard 6y agoWhat protocol would you choose for end-to-end encryption, Double Ratchet Algorithm, or another lightweight one?
- jech 6y agoI haven't thought about it seriously, but I was thinking about simply using a shared key (PBKDF2, since that is implemented in the browser), with a symmetric cipher and HMAC. To tell the truth, I haven't seen much demand for end-to-end: this is a web application, so an attacker who controls the server can simply serve Javascript with a backdoor.
- pmaynard 6y agoMakes sense. WebRTC seems to address a lot of the security concerns [1], and with it being a web-application served remotely, not much need for e2e. Though, if you were to host the application locally, and manage the updates yourself you may want to have some form of e2e. [1] https://webrtc-security.github.io/ https://webrtc-security.github.io/