HN
Hacker News
Top
New
Best
Ask
Show
Jobs
Comment by u48998 | Hacker News Reader
Parent
Full thread
u48998
·
Seems useful.
View on HN
Breefield
·
Why not just have users type in a room name and password on creation...no need to set the salt after the fact.
mtogo
·
Except that the encryption is handled with javascript (obviously). I wouldn't use this for anything serious.
magikarp
·
Why not? AES has been implemented in javascript half a dozen times.
tptacek
·
And? What is that evidence of?
sorbus
·
That the implementation of an encryption library in Javascript is not a reason to mistrust services which use that library?
tptacek
·
It isn't evidence of that. Implementation in
browser
JS
is
in fact a reason to distrust a cryptosystem.
mtogo
·
Okay..? What difference does
that
make?
cranklin
·
because... the server might send a broken .js therefore forcing your chat client into sending plain text.
mtogo
·
Exactly, that's the point. Or a browser extension. Or various other fun things, see tptacek's conversation above.
Reply on news.ycombinator.com