3 ms·
I haven't thought about it seriously, but I was thinking about simply using a shared key (PBKDF2, since that is implemented in the browser), with a symmetric ci
by jech 6y ago
I haven't thought about it seriously, but I was thinking about simply using a shared key (PBKDF2, since that is implemented in the browser), with a symmetric cipher and HMAC.
To tell the truth, I haven't seen much demand for end-to-end: this is a web application, so an attacker who controls the server can simply serve Javascript with a backdoor.
- pmaynard 6y agoMakes sense. WebRTC seems to address a lot of the security concerns [1], and with it being a web-application served remotely, not much need for e2e. Though, if you were to host the application locally, and manage the updates yourself you may want to have some form of e2e. [1] https://webrtc-security.github.io/ https://webrtc-security.github.io/