4 ms·
Have any of those libraries been audited so far? Seems like a necessary step for widespread js crypto.
by benzim 13y ago
Have any of those libraries been audited so far? Seems like a necessary step for widespread js crypto.
- rarrrrrr 13y agoSJCL had substantial peer review during its development, but I'm not aware of a public 3rd party audit from a security firm. Oh yeah, and before people with torches show up, let me clarify that is a Javascript based crypto product but not browser and website based crypto. The deployment target is situations where the code delivery problem is solved: HTML5 mobile apps (including phonegap / cordova), desktop apps with things like AppJS, browser extensions, etc. It's a high level secure-by-default framework for building collaborative realtime and storage applications. Javascript is a natural language for this, because the framework provides storage through an object database, and that approach is natural an convenient in Javascript. We're spending the time and money to make a secure framework now so we don't have to spend quite as much time in reinvention and security review for each new crypto application we build.
- tptacek 13y agoSJCL has been audited. You should ping me via email if you're serious about arranging for OSS crypto to get reviewed, not because I want to sell you audit services, but because someone already beat you to the punch in a big way, and you should talk to them. :)
- sasas 13y agoSo to be clear - we are not implying that these routines should be used in the browser right? http://www.matasano.com/articles/javascript-cryptography/ http://www.matasano.com/articles/javascript-cryptography/
- deezthugs 13y agoNot that we can find evidence of. SJCL is written by some of the best security people around. I have confidence in it - running in a "safe" runtime like a cordova app or extension. This is a library used by so many - it makes sense to try to crowd-fund an ongoing set of audits.