3 ms·
I cannot do that from inside the sandbox, but as I completely control the page, not just one script on it, I can be reasonably sure no rogue script is running o
by trekkin 14y ago
I cannot do that from inside the sandbox, but as I completely control the page, not just one script on it, I can be reasonably sure no rogue script is running on it (by using SSL).
I've read the Matasano article, don't assume I didn't. Most of the points in it are negated by controlling the page 100% and using SSL.
- tptacek 14y agoI'm confused. In way does your application protect users against you? You control the code that handles the users encryption secrets. Your users have no effective way to police you. Why not just have the users send you their plaintext, and rely on SSL/TLS for the rest of your security? It seems like that provides effectively the same security.