3 ms·
what about distributed as signed browser extensions?
by peterbraden 12y ago
what about distributed as signed browser extensions?
- danielweber 12y agoWhat's that Google is working on, and it's a much better environment. The code lives on your computer all the time, and you (in theory, assuming the proper browser settings) can make sure you are using a constant version of the code that matches up with what other people are using and auditing. You can't lock down JavaScript at all. Your browser should (in theory) tell you when a plug-in is asking to be updated and give you the option to say "nope." In theory, you could even walk up to a brand-new (assuming uncompromised) computer and reinstall the plugin. But you would still need some way of knowing that you were installing the same version you decided to trust earlier. Recognizing checksum pictures, I guess?
- xxs 12y agoIt can work but the users have to be able to 'read' the code from the server and sign it themselves. Certain hashes can be considered trustworthy and that would require a 3rd party or being able to put those hashes on paper and compare them.
- tptacek 12y agoI would say that signed browser Javascript extensions are my least favorite place to viably deploy crypto.