6 ms·
From link 2: "I have only heard of one application of JS crypto that made sense, but it wasn’t from a security perspective. A web firm processes credit card nu
by dan_manges 15y ago
From link 2:
"I have only heard of one application of JS crypto that made sense, but it wasn’t from a security perspective. A web firm processes credit card numbers. For cost reasons, they wanted to avoid PCI audits of their webservers, but PCI required any server that handled plaintext credit card numbers to be audited. So, their webservers send a JS crypto app to the browser client to encrypt the credit card number with an RSA public key. The corresponding private key is accessible only to the backend database. So based on the wording of PCI, only the database server requires an audit."
- y0ghur7_xxx 15y agoThanks. I've read his post a few months ago and completely forgot that paragraph.
- JimmyL 15y agoFor completeness, the next two paragraphs in Lawson's post: "Of course, this is a ludicrous argument from a security perspective. The webserver is a critical part of the chain of trust in protecting the credit card numbers. There are many subtle ways to trojan RSA encryption code to disclose the plaintext. To detect trojans, the web firm has a client machine that repeatedly downloads and checksums the JS code from each webserver. But an attacker can serve the original JS to that machine while sending trojaned code to other users. While I agree this is a clever way to avoid PCI audits, it does not increase actual security in any way. It is still subject to the above drawbacks of JS crypto."