3 ms·
AFAIK, the server does not rekey AES every 500ms - and your suggestion to use a server over TLS opens you up to the problem of the server itself being able to r
by magikarp 15y ago
AFAIK, the server does not rekey AES every 500ms - and your suggestion to use a server over TLS opens you up to the problem of the server itself being able to read all plaintext.
- tptacek 15y agoThe server can read all the plaintext anyways.
- magikarp 15y agoRight...
- magikarp 15y agoNo it can't, that's the whole point! Are you trolling?
- tptacek 15y agoNo, what's happening here is that that you don't actually understand the threat model for encryption code running in Javascript fed by a server, and you're getting more and more frustrated by the fact that I'm not handholding you through it. Reasoning about security systems (click my name to see that I do that for a living) is frustrating. To see what's happening in this case, steel yourself for a headache, sit down, and think hard through all the different things that attackers can potentially influence. Then ask yourself, "what could an attacker accomplish by manipulating that thing?".