4 ms·
> When this response was written, the blog post said nothing of the sort. In fact, in that point the text has not been changed whatsoever. Allow me to quote fr
by magikarp 13y ago
> When this response was written, the blog post said nothing of the sort. In fact, in that point the text has not been changed whatsoever.
Allow me to quote from the blog post: "In fact, I believe that it is necessary to deliver JavaScript cryptography-using webapps as signed browser extensions, as any other method of delivery is too vulnerable to man-in-the-middle attacks to be considered secure."
> While it is theoretically possible to accomplish secure client-side crypto given enough constraints, this does not map well to reality.
Well, in my case, we got our browser plugin audited by Veracode and things worked out.
- daeken 13y ago> Allow me to quote from the blog post As I said, that point (the one you quoted me on originally) does not make mention of signing, and the quote you gave there did not exist when I wrote the comment, as you well know. This is silliness of the highest order. > Well, in my case, we got our browser plugin audited by Veracode and things worked out. "Things work out" until they don't. As a fellow security professional, you should know as well as I do: no matter how many audits you do, you're still fucking something up, and someone will find it if it's valuable enough to do so. This is as true of your code as it is mine or anyone else's.