Also, as a non-security person, just how secure is this? Like is it used more for "eh, I don't really want something to see this, but it's not the end of the world if they do" or more like "yeah, use this for extremely secure content, it's safe."
Also, as a non-security person, just how secure is this? Like is it used more for "eh, I don't really want something to see this, but it's not the end of the world if they do" or more like "yeah, use this for extremely secure content, it's safe."
The encryption itself is solid (assuming it is implemented correctly and as described, I've not inspected the code) but as mentioned a short pass phrase combined with predictable plain text format would make this quite easy to brute force.
Also, you can't revoke access (again, without site-wide re-encryption).
An interesting POC, but not something that is really practical for broader use.
Even when you manage to keep the key secret I can't revoke your access to the material or prevent you re-transmitting it to others.
It's a hard problem, and this is certainly a novel solution to that problem, but I still don't really see myself using it.
/s
My guess is it's about as secure as putting an encrypted file on the internet. Except this has almost all the information you need to know how it was encrypted. Plus it has a useful guess-the-password form. There is no attempt-limiting or rate-limiting if you can download the file.
It's probably good enough for stuff like an informational product that you want to put behind a password but not good enough for storing your credit card details.
longer answer: look at the last script tag in the demo page, it exposes the encrypted HMAC string, the encrypted HTML text, the encryption method and even the library used to decrypt. You can easily brute force the passphrase
...or better yet embed some code in a popular web page and have the netizens brute force it for you (distributed computing).
In general, client side obfuscation is difficult to perform securely as it shares too much information to be secure.