4 ms·
> without involvement of any server > bypassing the need for centralized servers I don't follow this part... it's using a centralized server to serve the web
by ramchip 2y ago
> without involvement of any server
> bypassing the need for centralized servers
I don't follow this part... it's using a centralized server to serve the web app, which could easily serve JS code that steals confidential data right?
- dkraj 2y agoDidn't get the part of steals confidential data? It can not do anything without your permissions. All websites are well scoped and run in their private environment in a web browser.
- ramchip 2y agoI mean the data people send through the app. You say: > It is a p2p files and messages sharing platform without involvement of any server. It has end-to-end encryption, ensuring your messages and files remain confidential. However the clients get the JS code from the web server. Since you control that server, you can change the code to disable the encryption, or send a copy of the messages somewhere else. You can even make the server give specific people / IPs one copy of the code and others a different copy. Hence my point is there is a trusted centralized server involved.
- dkraj 2y agoGot you so you want to say that the place where I have hosted is a centralised place and yes you are right. But I won't do that ~~~
- supportengineer 2y agoSure “you” won’t do that. But who are you? What if “you” changes? “You” could be the CIA or a Nigerian scammer. Nobody knows. And it can change at any moment.
- scrose 2y agoAh yes, we should completely trust the anonymous person who registered to the site 23 days ago and has done nothing other than submit half a dozen chrome extensions to the site since then
- jfoster 2y agoThat is true, but unless you develop an application yourself, it is always coming from somewhere else. Web apps are better than native apps from a security perspective. Browsers have fairly decent built-in debugging tools that you could use to verify that data isn't being uploaded to a 3rd party. On the other hand, to do the same with a native application you would need to use a separate network protocol analyzer application. Web apps also run in a sandbox that users tend to have fairly good knowledge about. For example, they generally cannot access any file on your device unless you grant permission. What are the limits of the iOS, OSX, Android or Windows application sandboxes? Can apps on those platforms access files without explicit permission? I think the vast majority of users wouldn't be able to tell you.
- Retr0id 2y ago> Web apps are better than native apps from a security perspective. This isn't true. Sure, they have less access to the host system, but verifying the integrity and authenticity of a web app is harder than that of a native app, where code signing is commonplace (not that code signing is a whole solution, but it's a great start). Extensions[0] exist to improve the situation but it's not yet broadly applicable. A compromised web app doesn't have to upload your data to a 3rd party, it just has to (for example) encrypt with weak keys. You'd never notice that from the network logs alone. And while I agree that debug tooling for the web is great, there's a lot of great stuff for native code too. Ignoring "expert" tools entirely, a more user-facing example is Little Snitch[1], which handles the "detect data being sent to 3rd parties" use case. [0] https://engineering.fb.com/2022/03/10/security/code-verify/ https://engineering.fb.com/2022/03/10/security/code-verify/ [1] https://www.obdev.at/products/littlesnitch/index.html https://www.obdev.at/products/littlesnitch/index.html
- hombre_fatal 2y ago1) For ~everyone, the authenticity check for an app is simply whether it exists on an app store. I think the only time I ever checked the signature on software outside the app store is for my bitcoin wallet. 2) Legit trusted applications are already what siphons everyone’s content, not malware. At least in the browser there’s uBlock Origin and even a dev console. Just some things to keep in mind when comparing the differences.
- deleted 2y ago[deleted]