3 ms·
This is a deck by Ben Adida (formerly of Mozilla, where he led the Persona project and now at Square) explaining how that argument is reductionistic. https://d
by notwhyships 13y ago
This is a deck by Ben Adida (formerly of Mozilla, where he led the Persona project and now at Square) explaining how that argument is reductionistic.
https://docs.google.com/presentation/d/1bLBb0EIJ0cuoAhsmI1XLRj1QfGlGTfofJwlemqaP-hM/edit?pli=1#slide=id.g665e5ab7_0_5 https://docs.google.com/presentation/d/1bLBb0EIJ0cuoAhsmI1XL...
- rosser 13y agoCan you please help me find even an argument in that deck, let alone any refutation? Did I get an incomplete deck, perhaps? The version I'm seeing stops at slide 22.
- notwhyships 13y agoThere are 22 slides. It's admittedly terse (it was part of a presentation Ben Adida gave at the first Real World Cryptography workshop). However, I'd suggest reading the deck again, and while you do asking yourself, does JS crypto provide any security beyond what SSL does? And, can JS crypto make sense as part of a defense in depth/layered security approach?
- bmm6o 13y agoHe's presumably referring to slides 17-20. It essentially boils down to "JS crypto in the browser is better than nothing".
- rosser 13y agoBut it's not — at least not necessarily. That's the problem. It creates a potentially incredibly dangerous false sense of security, and nothing in the deck refutes that, or even argues against it.