2 ms·
We implement OpenPGP client-side, on the user's devices. Their central complaint of > If it’s running in the browser with code downloaded from our servers, the
by twiss 2y ago
We implement OpenPGP client-side, on the user's devices. Their central complaint of
> If it’s running in the browser with code downloaded from our servers, then if we get compromised, we can serve up a version of the PGP code which leaks keys or plaintext.
is well-known but only applicable to the web app, the other clients are less susceptible to this. Even for the web app, we are proposing to solve this problem: https://github.com/twiss/source-code-transparency https://github.com/twiss/source-code-transparency
- marcus_holmes 2y agothanks for the clarification. I'm a happy Fastmail user, but I appreciate that other people have different ideas