4 ms·
Does anyone here have experience with turtl? Pros/cons? Confidence in security model?
by yanowitz 13y ago
Does anyone here have experience with turtl? Pros/cons? Confidence in security model?
- foobarqux 13y agoThe security model is broken. You can't securely do encryption in server side javascript.
- orthecreedence 13y agoIncorrect, my friend! There's no server-side javascript. Turtl is a downloaded, self-contained app, and all encryption happens in that app.
- foobarqux 13y agoSorry, my mistake. I guess I just assume everything is a webapp these days.
- SomeoneWeird 13y agoMay I ask why you think that is?
- orthecreedence 13y agoIt's true you can't reliably do crypto in javascript served from a web server. The idea is that someone could hack into your server, replace `crypto.aes.js` with `crypto.plaintext.js` and suddenly your app is silently sending plaintext back to the server where ciphertext is expected. The correct way is to create a (signed) package of your app so that it pulls in no external scripts or files. Makes updates a pain (no free auto-upgrades you get from the web) but makes the app a lot more difficult to attack.