3 ms·
i like the effort guys, but secure web apps is a tall order. the attack surface of a web app is huge and the web was just not built for client-side crypto. the
by conformal 13y ago
i like the effort guys, but secure web apps is a tall order. the attack surface of a web app is huge and the web was just not built for client-side crypto. the dependency list for most web browsers is gigantic and attacks against even one of the deps could lead to your crypto being blown.
keep in mind that cryptocat had been audited at least once and they totally missed the completely-busted prng. i am betting you guys will do a better job than nadim et al :)
- ecto 13y agoTotally agree. The idea is to provide a centralized place for the crypto work to happen, which while perhaps quixotic is arguably better than 100 developers creating potentially broken cryptosystems independently. We've stayed abreast on the cryptocat issue - we're using SJCL which uses a derivative of the Fortuna PRNG http://bitwiseshiftleft.github.io/sjcl/doc/symbols/sjcl.random.html http://bitwiseshiftleft.github.io/sjcl/doc/symbols/sjcl.rand...