3 ms·
just write the Mozilla and Chrome extensions to expose a C implementation of PGP/GPG to Javascript? Would that really help? The same hypothetical malicious ser
by CodeMage 14y ago
just write the Mozilla and Chrome extensions to expose a C implementation of PGP/GPG to Javascript?
Would that really help? The same hypothetical malicious server admin could simply alter the JS to not call the code from the extension and the average user would be none the wiser. What am I missing?
- mike-cardwell 14y agoIf the crypto operations are run in browser elements that are obviously part of the browser chrome and not the webpage, then they should be safe. As long as the end user knows the difference. Eg, if the end user knows they can safely write a message and hit an encrypt button in a particular window opened by the browser, but not just any old textarea on the webpage.