Hacker News new | past | comments | ask | show | jobs | submit login

Relevant: http://rdist.root.org/2010/11/29/final-post-on-javascript-cr...

The killer for me has always been #7 on Nate Lawson's list: Auditability. How do you tell that your browser is using the right copy of the code to do the crypto?




This is an excellent article on this subject. The author (Nate Lawson) is thorough in his argument. His conclusion is "I am certain JS crypto does not make security sense."


This should be at the top.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: