HN
Hacker News
Top
New
Best
Ask
Show
Jobs
Comment by attilak | Hacker News Reader
Parent
Full thread
attilak
·
Nice idea, sadly only as secure as https.
View on HN
eliaskg
·
As all clients need a password to enter a room, the messages could be encrypted with that password. There are a lot of JS libraries that could do this, e.g. Triplesec
icebraining
·
http://matasano.com/articles/javascript-cryptography/
knadh
·
Author here. Right now, it's only as secure as https, but I'll look into JS encryption. It's just a fun project that came out of some Go experiments.
lclarkmichalek
·
Still would only be as secure as https if the client is downloading your JS crypto lib every visit.
attilak
·
Would it be safe to keep the crypto lib on the client somehow? Browser addon? local storage? How would we do that?
rakoo
·
https://webpg.org/
Reply on news.ycombinator.com