3 ms·
How else would you do client side crypto for a website if not with JavaScript, isn't that kind of the point of how Proton does E2EE?
by devman0 2y ago
How else would you do client side crypto for a website if not with JavaScript, isn't that kind of the point of how Proton does E2EE?
- stavros 2y agoCrypto for websites is completely broken (because the server can serve you whatever it wants), so doing crypto for websites at all is suspicious.
- iknowstuff 2y agoI guess they have this for local email decryption: https://proton.me/mail/bridge https://proton.me/mail/bridge idk if they have anything like that for their other products like calendar or file storage Presumably if you stick to mobile apps you won't be using JavaScript served by their server? Unless they're just html wrappers
- ranger_danger 2y agoIt's not "broken", please don't spread FUD. It's a whole lot more transparent than doing it on the server side. Client code can be inspected and publicly audited, and many times you can save/cache it so that it doesn't change. Also opens up the possibility for third party standalone apps that don't change often.
- akimbostrawman 2y agothis can be mitigated by using a browser addon to calculate and verify the web js content is matching the hash in a public code repo. That is how CTemplar Mail does it. I'm disappointed they haven't implemented something like this.
- ranger_danger 2y agoWASM? I have seen it used a lot for this.