Show HN: Deadrop.us
deadrop.us
deadrop.us
http://www.matasano.com/articles/javascript-cryptography/
(The OP's page has third-party javascript loading onto it (Google Analytics).)
Why can't I use TLS/SSL to deliver the Javascript crypto code?
You can. It's harder than it sounds, but you safely transmit Javascript crypto to a browser using SSL. The problem is, having established a secure channel with SSL, you no longer need Javascript cryptography; you have "real" cryptography.
So, you can deliver the JS to the browser securely!
It doesn't matter if you are running server-trusted JS crypto in your browser, or server-encrypted data. Either way, the server is dictating the code/algorithms in use, and could backdoor/subvert the encryption.
edit: sneak points out that you have Google Analytics loading on that page, so your data could be compromised that way - theoretically :)
Nope. The server operator can still serve you (perfectly secured over an SSL channel) backdoored javascript crypto code.
Like:
Store content securely in a Drop
1. Get your URL 2. Store content 3. Set password
-> then you can have a link that explains how it works and why this is super secure.
Here's another that opensourced their code last week: http://pwpush.com/
{"iv":"6p7sXVuJe+MR9EcAvSYNxQ","v":1,"iter":1000,"ks":128,"ts":64,"mode":"ccm","adata":"","cipher":"aes","salt":"A+pgCtAsfyQ","ct":"DNsHqh4bMEs"}