It needs client-side code to do it correctly, for example, something like the e2e Chrome extension.
It needs client-side code to do it correctly, for example, something like the e2e Chrome extension.
(And practically speaking, before building Cyph, Josh and I pretty much avoided having to use encryption except in cases where there was no alternative.)
But I definitely agree that we'll have to come up with a clever solution to this problem. Off the top of my head (haven't thought this through — could be totally stupid), we may be able to do something clever with html5 appcache and notifying users when the hash of the code changes (and giving them the option to stay on their known good version).
Of course, once we have our native app out this issue will be trivial to avoid for people who really need to.
Edit: To clarify, I should correct you on that we are definitely performing the end-to-end encryption from the client — anything else would kinda defeat the purpose of Cyph...