Skip to content

Comment on A secure way to store website users "offsite" but still own them.parent

Comments

I know that serving up ribeyes carved off sacred cows is your schtick and all, but on this issue you're just wrong. Browser javascript is the most hostile environment crypto is deployed in today; it's worse even than microcontrollers that have to use CBC-MAC because SHA1 won't fit in code space. It doesn't work.

I'm writing up a document about this now, as luck would have it, but in the meantime you could try not taking my word for and instead read Nate Lawson, who is smarter than both of us put together:

http://rdist.root.org/2010/11/29/final-post-on-javascript-cr...

Here's a hint: it's not about "encoding issues". SJCL is nice work, but SJCL is to a working cryptosystem what mixed oxide U/Pu fuel pellets are to a working nuclear reactor. Don't be like that boy scout who irradiated his whole suburb building something in his garage.

You know what Thomas, you're right I'm being douchey. I'll work on making this a bit better, and report on what I find.

Thanks for your comments so far.

I had it coming. But for what it's worth: I'm a net admirer of your work. Call me out for being unfair any time, but don't think I'm throwing darts at a Zed Shaw picture on my wall.

Why not build it into the browser? Firefox already exposes a window.crypto object.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.