4 ms·
That has nothing to do with javascript-the-language, but rather the way the web works. Obviously even with https, javascript delivered by a web server has a vul
by yafujifide 12y ago
That has nothing to do with javascript-the-language, but rather the way the web works. Obviously even with https, javascript delivered by a web server has a vulnerability whereby the web server may be compromised, which is outside of the users control. Any javscript delivered by a web server should be executed with that understanding. i.e., delivering a wallet from a web server is probably not the right thing to do. Note that javascript can also be run in the form of a browser extension, server-side node, node-webkit, apache cordova, etc. Javascript-the-language is not intrinsically vulnerable to a compromised webserver.
- Sir_Cmpwn 12y agoIt's fair to say that JavaScript-the-language is not intrinsically vulnerable to this, but how else are you planning on delivering the JavaScript to clients? I may be misinterpreting your goals.
- yafujifide 12y agoNot in the form of a webapp. It would have been a browser extension and/or mobile.
- Sir_Cmpwn 12y agoThanks for clarifying.
- tptacek 12y agoThis seems pretty much correct.
- jsprogrammer 12y agoA usable browser implementation of a wallet could be secured fairly well and if it gained any popularity would put pressure on browser makers to deliver better solutions.