4 ms·
The bigger problem is that this model is inherently flawed. Even if end-to-end encryption with browser crypto were implemented, there is never any security sinc
by pareidolia 10mo ago
The bigger problem is that this model is inherently flawed. Even if end-to-end encryption with browser crypto were implemented, there is never any security since the code in the browser can simply be swapped with compromised code that diverts the plaintext somewhere.
I've been forced to use this service, by way of healthcare professionals just disclosing correspondence to this service without asking for my consent.
Smeerlappen.
- _el1s7 10mo agoSecurity is an illusion.
- pareidolia 10mo agoThen reply with your passwords.
- sallveburrpi 10mo ago****** Luckily HN automatically detects when you post your password and obfuscates it with * - try it out yourself!
- pareidolia 10mo agoYou think I was born yesterday :P
- Mordisquitos 10mo agohunter2
- Mordisquitos 10mo agoDoesn't look obfuscated to me.
- throw310822 10mo agoIt only obfuscates it for others :)
- KaiserPro 10mo agoThats the genius of it, to us it looks like **** but you see hunter2. Its an automatic replace.
- balex 10mo agoOh whew, I thought he was using hunter2 as his password too.
- tucnak 10mo ago> there is never any security since the code in the browser can simply be swapped with compromised code that diverts the plaintext somewhere. This is not the case in the land of DICE-like key derivation; see TKey protocol for example. You can download and run an actual rv32 program on actual FPGA over WebUSB without having to worry about its provenance. If the program is modified, firmware will derive a completely different key.
- pareidolia 10mo agoZivver is a web application. The javascript that comes with the webpage can change at any time for any reason, as Zivver sees fit.
- tucnak 10mo agoI'm simply pointing out that web standards allow for secure end-to-end communication, and more, in fact they happen to allow arbitrary cryptographic constructions—as long as the program itself never changes.
- pareidolia 10mo agoBut this requires special hardware right?
- tucnak 10mo agoNot necessarily. You can run TKey in qemu :-) etc. The hardware aspect is what makes it easy to use, with WebUSB and all. The derivation algorithm is key. And it takes program binary as parameter to Blake2 hash function.