3 ms·
I disagree. Javascript cryptography can provide real security, it's just important to keep in mind what is being secured, and where the vulnerabilities are. C
by nlacasse 13y ago
I disagree. Javascript cryptography can provide real security, it's just important to keep in mind what is being secured, and where the vulnerabilities are. Currently, js crypto is vulnerable in that its difficult to verify that the js a browser is running is the intented code.
Every day, millions of people are sending sensitive data over very insecure channels like email and DropBox because secure tools like PGP are to difficult for them or their friends to use. Clearly some security is better than none, as long as the limitations are known.
- tptacek 13y agoThis is like saying a sign that says "attackers keep out" provides real security, as long as you keep in mind that it only works if attackers obey the sign. After all, Dropbox doesn't have an "attackers keep out" sign!
- azakai 13y agoNo, it's more like an imperfect lock is still more security than no lock at all on your door.
- DanBC 13y agoNo, it's more like people thinking they have a high grade lock on their door, when in fact they have a broken lock. They can't see it's broken, but anyone who knows about locks knows it's broken, and how to bypass it with a bobby pin.
- eldondev 13y agoIs this supposed to be serious, because we want javascript to be better, or sarcastic, because most people DO live behind locks that are broken and can be bypassed trivially with relatively unsophisticated tools? Everybody break out your bobby pins!
- nwh 13y agoYou would have extreme trouble picking a lock with a bobby pin, they're much too fat to do anything outside of a movie.
- Spooky23 13y agoIt is a little better than that. What about an enterprise application where you have control/trust of the server, but want to securely cache data in offline browser storage. That covers common scenarios, like people who provide web based access to Microsoft Exchange.