4 ms·
May I ask why you think that is?
by SomeoneWeird 13y ago
May I ask why you think that is?
- orthecreedence 13y agoIt's true you can't reliably do crypto in javascript served from a web server. The idea is that someone could hack into your server, replace `crypto.aes.js` with `crypto.plaintext.js` and suddenly your app is silently sending plaintext back to the server where ciphertext is expected. The correct way is to create a (signed) package of your app so that it pulls in no external scripts or files. Makes updates a pain (no free auto-upgrades you get from the web) but makes the app a lot more difficult to attack.