4 ms·
We (SpiderOak) have been working on a framework called Crypton[1] for the last few months that allows you to create cryptographically secure web apps. We're try
by ecto 13y ago
We (SpiderOak) have been working on a framework called Crypton[1] for the last few months that allows you to create cryptographically secure web apps. We're trying to get the 0.2 release and new website[2] out this week.
I'm currently the only dev on the project and we could always use more eyeballs. I'm working through a code review right now to improve the existing features, but I'm also half way done implementing shared containers and realtime public key messaging. The idea is that you don't new to understand the crypto if you use the framework. We are in the process of getting a professional security audit.
[1] https://github.com/SpiderOak/crypton https://github.com/SpiderOak/crypton
[2] https://crypton.io https://crypton.io
- hoodoof 13y agoWhat about the security of the host your system is running on?
- ecto 13y agoThis is obviously an issue. Users are never going to read and verify every line of code that comes over the wire, so in the end it comes down to trust and vigilant sysadmins.
- conformal 13y agoi like the effort guys, but secure web apps is a tall order. the attack surface of a web app is huge and the web was just not built for client-side crypto. the dependency list for most web browsers is gigantic and attacks against even one of the deps could lead to your crypto being blown. keep in mind that cryptocat had been audited at least once and they totally missed the completely-busted prng. i am betting you guys will do a better job than nadim et al :)
- ecto 13y agoTotally agree. The idea is to provide a centralized place for the crypto work to happen, which while perhaps quixotic is arguably better than 100 developers creating potentially broken cryptosystems independently. We've stayed abreast on the cryptocat issue - we're using SJCL which uses a derivative of the Fortuna PRNG http://bitwiseshiftleft.github.io/sjcl/doc/symbols/sjcl.random.html http://bitwiseshiftleft.github.io/sjcl/doc/symbols/sjcl.rand...