2 ms·
1. I think the best option is for the client to encrypt using a local library, like NaCl before sending anything to the server. The server should not provide t
by gry 12y ago
1. I think the best option is for the client to encrypt using a local library, like NaCl before sending anything to the server. The server should not provide the encryption algorithm. The client and server must agree in the algorithm, but neither provide it.
2. Yes, it defers trust and responsibility. Now Mozilla, Google, Apple, Microsoft, and Opera are on the lam for issuing a competent browser encryption.
The messed up thing is, all it does is defer trust. What I'm trying to say about the current state of client-side web crypto as far as I understand it, deferring trust doesn't do a damned thing. It's still the source of the crypto lib, which is you.
EDIT: clarity
- superuser2 12y agoOT, but: on the hook. On the lam means you are trying to escape (re)capture by the legal system.
- gry 12y agoThanks, you're right. I've misused the word for ages.