4 ms·
Thanks, I hadn't seen that one yet. There are issues with javascript crypto[1] which is why we didn't go in that direction. [1] http://matasano.com/articles/ja
by delano 14y ago
Thanks, I hadn't seen that one yet. There are issues with javascript crypto[1] which is why we didn't go in that direction.
[1] http://matasano.com/articles/javascript-cryptography/ http://matasano.com/articles/javascript-cryptography/
- chacham15 14y agoThe problem with that article is that the author assumes that the only purpose for javascript cryptography is so that no middle man can understand the content, not the server itself. Javascript cryptography in this context is a more difficult problem only because you must trust that the code that the authentic source delivers does itself not contain a backdoor to the information.
- jstalin 14y agoI'd rather trust the javascript code that I can review than believe that whatever is happening on the service side can be trusted.
- delano 14y agoBeing cautious is important but keep in mind that the goal here is to be a replacement for having plaintext, sensitive info in your email history and chat logs. We've all seen these: http://plaintextoffenders.com/ http://plaintextoffenders.com/
- delano 14y agoYou raise a good point. I'm not against encryption in the browser as a rule but it does open up a whole new can of worms. Our approach is to be just good enough for most usecases.