Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

CryptoJS is security theater, too. Doing crypto in JavaScript in a browser is never secure.

An application with a silent update mechanism has the same problem. An update mechanism that tells you its happening and waits for your approval does not.



What about browser's (says Chrome) auto update feature? Security theater too?


Becomes more difficult to say. I would suggest that it is, yes. However, the tradeoff is more difficult to make, you have to decide if you trust Google not to push a sour update (but consider that it might be compelled to by a state actor). Also note that Chrome might have different secrets to share in the first place, it could just break future SSL connections or share saved passwords or something.

Personally, running Chromium on Linux, I don't get automatic updates and go through the usual process of signed updates from package maintainers only when I approve them.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: