3 ms·
I linked to that from https://paste.sh/about https://paste.sh/about -- creating pastes only works on browsers with crypto.getRandomValues (or with the command l
by dgl 13y ago
I linked to that from https://paste.sh/about https://paste.sh/about -- creating pastes only works on browsers with crypto.getRandomValues (or with the command line client).
Okay, there are still issues with the JS environment but this does eliminate one of the worst issues IMO
- tptacek 13y agoThe worst issue with JS cryptography is that it's almost always pointless, as it is here. Your users can't trust that you'll protect their secrets, because any coercive adversary who would ordinarily operate by copying those secrets off the server directly will instead simply force you to host a backdoor that breaks the crypto. That's the worst problem with JS crypto, but we haven't enumerated all of the problems on this thread, nor does my (old) post on our website do so either.
- tokenizerrr 13y agoIt's open source and can be self hosted. With proper SSL would you still consider it pointless in that case?
- tptacek 13y agoYes.
- dgl 13y agoI wouldn't call it pointless, I think it's better than not having it at all.