Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why not? AES has been implemented in javascript half a dozen times.


And? What is that evidence of?


That the implementation of an encryption library in Javascript is not a reason to mistrust services which use that library?


It isn't evidence of that. Implementation in browser JS is in fact a reason to distrust a cryptosystem.


Okay..? What difference does that make?


because... the server might send a broken .js therefore forcing your chat client into sending plain text.


Exactly, that's the point. Or a browser extension. Or various other fun things, see tptacek's conversation above.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: