Javascript and crypto. Am I on a fool's errand?
I'm working on a little project that uses the openpgpjs library[1]. After seeing the epic shitstorm here[2] it's got me worried about whether or not I'm doing the right thing and whether or not I should release it at all.
I'm a security person, a pentester but not a pro cryptographer. My project involves using symmetric and asymmetric OpenPGP encryption in the browser, not on the server - hence Javascript. Java libraries like bouncycastle seem to be available but to me I don't see much of a difference between Java and Javascript implementations (without formally reviewing both, neither of which I'm qualified to do from a crypto perspective) beyond the fact that no-one wants to use Java unless they have to.
So my question is, should I carry on with my project but open it up to cryptographers I know to evaluate before public release or am I on a fools' errand using Javascript? If so, why?