3 ms·
"As in who cares about security enough to encrypt their messages but not enough to install a standalone client, which has a stricter security model." this is s
by conformal 14y ago
"As in who cares about security enough to encrypt their messages but not enough to install a standalone client, which has a stricter security model."
this is so spot on. secure comms have no place in a web browser, which is a complex beast with a large set of underlying dependencies. webkit vulnerabilities leading to comms being blown is a crappy architecture.
people who care about comms use a standalone client and a separate server. if you care about the integrity of the server, you run some disk crypto, DDR3 memory, secure it physically, etc.
- sweis 14y agoAre you recommending DDR3 memory because you think it's resistant to cold boot or reset attacks? That is not the case. DDR3 memory will not help you.
- Klinky 14y agomaybe they meant ECC memory?
- randomchars 14y agoIs ECC more secure than regular consumer grade memory?
- rdl 14y agoMore "secure" from single bit errors, but not for recovery -- kind of the opposite goal. The big difference is DRAM (mostly the same, including DDR3) vs. SRAM (of several types -- relevant due to use in HSMs, cpu cache, etc.). DRAM has been getting worse/longer duration as it becomes lower power, so arguably DDR3 (being relatively new) would be worse than 1985 RAM. CPU registers are the safest place against this attack (hence stuff like TRESOR where AES keys are held in CPU registers), but are by necessity limited (especially on x86; SPARC was better, and some of the new extensions to x86 help (SSE, etc.) Most of this has been mitigated to some extent by periodic inversion of sensitive strings in main memory (keys, usually) -- this has been implemented in ~all crypto libraries. SRAM's huge advantage is you can clear it faster than DRAM, but that doesn't help if you can somehow prevent the clearing from happening.
- rdl 14y agoCertainly DDR3 memory (as a type of main memory) has less permanence than hard disks (i.e. secondary storage). It's a side effect not a desired goal. Especially if you're bit-flipping sensitive stuff, there's probably a good hope for protection from recovery at normal temperature after what, 30-60 seconds? So reset is an issue, but "keep sensitive things in RAM vs. on disk" is still a reasonable security precaution.
- lifebar 14y ago"secure comms have no place in a web browser," Agreed. Any good stand alone stuff you could suggest? Also, why cryptocat is browser plugin? Why not also make stand alone version? Like with contacts and such ( I know aka "skype with list of contacts you have secret conversations with that you don't want anyone to know about" would be silly but would have it's uses if it would also keep cryptocat style of "join public room and then go to private conversation")