[HN Gopher] Web-based cryptography is always snake oil
___________________________________________________________________
Web-based cryptography is always snake oil
Author : sanj
Score : 7 points
Date : 2025-03-27 21:05 UTC (1 hours ago)
(HTM) web link (www.devever.net)
(TXT) w3m dump (www.devever.net)
| afarah1 wrote:
| Yes, web crypto requires trust on the server and is not secure if
| your threat model includes its compromise (or that of the CA).
| ProtonMail recognizes this[1] and offers native open source
| clients. They also try to somewhat reduce the issue by using an
| SPA for the web client, to reduce fetches from the server.
|
| [1] https://vimeo.com/216747532 2017 presentation by ProtonMail's
| CTO saying essentially the above, at 50:41
| proxynoproxy wrote:
| I wouldn't call this "incoherent" rather, I propose the
| terminology "vendor subvertable".
|
| Yes, any time a vendor of software has any direct update
| capabilities, a targeted update can bypass the encryption
| provided by some software.
|
| In practice, we tend to delegate to a 3rd party like an OS
| distribution packager, where there is a delay between vendor
| releases and packaging. Where it can be discovered.
|
| Another good reason to use open source for core cryptography
| libraries and any code a vendor supplies should be open and
| repeatably built also.
___________________________________________________________________
(page generated 2025-03-27 23:01 UTC)