4 ms·
> that server is going to be able to read your plaintext no matter what. I'm truly sorry, I follow you on Twitter and actually really respect your opinion, but
by magikarp 15y ago
> that server is going to be able to read your plaintext no matter what.
I'm truly sorry, I follow you on Twitter and actually really respect your opinion, but that's just nonsense. the HTML, CSS and JS can all be verified, either by a plugin or by researchers studying what the server is sending, or by a variety of other ways. This ultimatum you're giving is silly.
> Yes. If you think China is intercepting your HTTPS traffic, remove all the root certs in your browser. Then browse to the key sites you're worried about protecting and create exceptions for each of them. China will not be able to use "fake certs" to intercept traffic to those servers.
That is not a real solution.
> Yes. In cryptosystems, 10+ years of study does count for a lot.
Of course - I never suggested it didn't - but that doesn't mean that new research can't undergo and survive skepticism.
- tptacek 15y agoYou just stuck a plugin into the mix. You can make crypto work from a browser plugin. Just use the plugin for all the crypto; what the hell is the point of Javascript cryptography if you have a plugin? That's reckless to the point of negligence. That is not a real solution. Neither is YOUR FACE.
- magikarp 15y ago...
- shiven 15y agoNeither is YOUR FACE We don't write comments like this here. Ref: https://news.ycombinator.com/item?id=2934523 https://news.ycombinator.com/item?id=2934523 Are you genuinely trying to be funny or is this OK coming from you on HN? Sorry if this appears kvetchy, but clearly I need to get the rules around here straight before I open my mouth again.
- tptacek 15y agoI'm joking. Next time you have a question like this, you can email me; I put my email in my profile.
- fadzlan 15y agoAlthough I don't really appreciates the tone here, I think that point that you are trying to make is that, if we are just going to use plugin, just use plugin all the way; why bother with Javascript for crypto at all.
- infinite8s 15y agoI think the point you are missing is that even if researchers/people can verify what the server is sending in general, there's no way for you to verify that the HTML/CSS/JS it sends you at that particular point in time is the same as the generally vetted version.