Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
trekkin
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
61.
▲
by
trekkin
14y ago
Which more or less translates into client-side encryption. Which some people here don't like, weirdly.
62.
▲
by
trekkin
14y ago
OK, let's discuss the article in detail. :) The article lists three reasons for why "JS crypto is bad" at the beginning: - Secure delivery of Javascript to browsers is a chicken-egg problem. - Browser Javascript is hostile to cryptography.
63.
▲
by
trekkin
14y ago
There are two issues here, I think. One is intentional leakage, or trusting the vendor to be "not evil". Here you are right - as you mentioned in another comment, there is no easy way for users to "police" the vendor of JS crypto. I do not
64.
▲
by
trekkin
14y ago
That is true - if the server side is compromised, all bets are off. However, how this is different from, let's say, a compromised browser update? And good luck with you app - client-side JS crypto needs more dev attention. :)
65.
▲
by
trekkin
14y ago
I cannot do that from inside the sandbox, but as I completely control the page, not just one script on it, I can be reasonably sure no rogue script is running on it (by using SSL). I've read the Matasano article, don't assume I didn't. Most
66.
▲
by
trekkin
14y ago
deadrop.us seems to be focused exclusively on short messages. aes.io, in addition to messages, supports file uploads and sharing, for example...
67.
▲
by
trekkin
14y ago
Thank you! The Matasano article, as I mentioned in another comment, for some reason assumes that SSL is not used, which is not the case with aes.io.
68.
▲
by
trekkin
14y ago
Not difficult in theory - classes not supported by GWT (such as iostreams) are easily cut out; but in practice many array operations inside BigInteger needed to be carefully tweaked to work well when compiled into JS.
69.
▲
by
trekkin
14y ago
The article assumes that the web service with JavaScript crypto is not using SSL. It explicitly says "And if you have SSL, why do you need Javascript crypto? Just use the SSL." aes.io uses SSL _and_ JS crypto on top of it to make sure serve
70.
▲
by
trekkin
14y ago
The article has many points, but it seems that they can be grouped together around three themes: 1. very easy for MITM-type attacks: this is negated by using SSL 2. JavaScript is too "malleable" for crypto - this argument is not very clear;
71.
▲
Show HN: aes.io - secure storage/collaboration with client-side JS crypto
(aes.io)
10 points
by
trekkin
14y ago
|
38 comments
72.
▲
by
trekkin
14y ago
Will do ShowHN when I'm allowed to (getting "You're submitting too fast. Please slow down. Thanks.") Re: OpenPGP vs PKCS1: historical reasons (have a well-tested code for PKCS1). If at some point it becomes clear that OpenPGP is much better
73.
▲
by
trekkin
14y ago
Disclosure: I'm the founder of aes.io :) To answer your questions: 1. all encryption/decryption is done in JS. BouncyCastle java source code is used (slightly tweaked for performance) - it is compiled into JS using Google's GWT compiler. 2.
74.
▲
by
trekkin
14y ago
SpiderOak (most similar to drive, dropbox), Tarsnap ( nix-only, have to compile it yourself), aes.io (browser-based, like box.com)
75.
▲
by
trekkin
14y ago
SpiderOak, Tarsnap, Dropbox + Truecrypt if you don't mind binary clients; web apps with client-side encryption such as aes.io if you don't want to install anything.
76.
▲
by
trekkin
14y ago
Well, I work at a Linux shop, and I don't know anyone who would buy an AMD laptop to run Linux on it. And it's been more than two months since IvyBridge release, so a laptop that runs SandyBridge is probably not technically new (it can be n
77.
▲
by
trekkin
14y ago
I have x230, and I have to use a custom kernel, as the standard Ubuntu 12.04 kernel (3.2.x) hangs all flavors (standard/Unity, xubuntu, lubuntu).
78.
▲
by
trekkin
14y ago
Actually, most of new laptops do not work out of the box with Ubuntu 12.04 - you need to manually compile and/or install a custom Linux kernel in order to avoid hanging, as it is documented here: http://partiallysanedeveloper.blogspot.com/
79.
▲
by
trekkin
14y ago
Exactly. Most VC funds don't bring in huge returns, but VCs still get their millions from those 2%.
80.
▲
by
trekkin
14y ago
Would spideroak be a better option then?