3 ms·
I'm not an authority on hushmail, but it seems like they do crypto on the server, and the server is just trusted to throw away the keys and plaintext? In the k
by maxtaco 13y ago
I'm not an authority on hushmail, but it seems like they do crypto on the server, and the server is just trusted to throw away the keys and plaintext?
In the keybase Web client, all crypto happens on the browser. The server knows no keys or data in plaintext. Of course, you'd have to audit the front-end JS code to believe that claim.
But our intention is that the only way to compromise the Web-based tools would be to insert malicious JavaScript into the client's browser. A read-only compromise of the server yields only encrypted data, and the server never has access to the decryption keys.
- sweis 13y agoAs you just said, users must trust the JS coming from Keybase. It might be compromised at any time. Next, people usually mumble about auditing it, downloading a copy, signing it, etc. At the end of the day, you arrive to code installed on the client - which you already have. The web version just weakens your story.
- aragot 13y agoBut it's a good idea: Sign the js. Even md5 would be enough, it's just so that when the FBINSA subpoenas you, we'll know it.
- tptacek 13y agoThen the only difference between hushmail and your model is exactly what the FBI will get a subpoena to have you type into your server to subvert your users. The models are equivalently insecure. Incidentally, you can't simply audit the "front-end Javascript"; you have to evaluate everything that influences the Javascript runtime (the DOM, stylesheets, cached resources, &c) every time the page loads. Browsers aren't designed to make content-controlled code "auditable"; it simply isn't a capability of the environment.
- chaitanya 13y agoFWIW, I found your post "Javascript Cryptography Considered Harmful" very helpful in understanding problems with client side crypto in the browser. I will recommend it to anyone who thinks it is safe: http://www.matasano.com/articles/javascript-cryptography/ http://www.matasano.com/articles/javascript-cryptography/
- e_proxus 13y agoAnd don't forget all extensions which can "Access all your data on all webpages, Access all your tabs and browsing activity".
- jessaustin 13y agoIf this functionality were provided by e.g. a signed extension (so the code can't be changed without the user being told: I think browsers can do this?), then you would worry mostly about how well that extension was sandboxed away from other extensions and various websites, right?