Why not use WebCrypto instead? No library needed.
OpenPGPjs has passed an independent security audit
31–40 of 128 posts
Re: OpenPGPjs has passed an independent security audit
#32Earlier quoted context omitted.
This (rightfully) comes up every time some browser-based encryption tool is posted. It seems like the desire for such tools isn’t going to go away. Is anyone working on solutions for making distribution of JavaScript applications more secure? There’s a range of assurances you could try to provide, e.x. signatures from the author (or even 3rd parties), prompting for updates, etc. It would likely require support from b…
Have a look at https://w3c.github.io/webappsec-subresource-integrity/
If you could require the root page be cryptographically signed (but by who?) and optionally prompted for updates then we’re talking.
Re: OpenPGPjs has passed an independent security audit
#33> The only limitations come from the platform itself (JavaScript/web), which do not allow for side channel resistance or reliable constant time operations. Overall however this is an exceptional library for JavaScript cryptography. How would this compare to something like WebCrypto, which assume would be implemented in a way that would allow for side channel resistance etc? It does seem surprising that we don't have…
Re: OpenPGPjs has passed an independent security audit
#34Not that it matters. They could silently replace it with a backdoored script and your browser would never tell you it happened. And to preempt the ProtonMail rep who is probably going to respond to this comment, I know that you can run the web app on localhost. But that doesn't mean that users who don't are any more secure.
The readme indicates that it can be installed via npm, so I'm not sure what your concern is. https://github.com/openpgpjs/openpgpjs/blob/master/README.md
Re: OpenPGPjs has passed an independent security audit
#35https://paragonie.com/audit/L7TtZbFoJBxR91Xg
I didn’t think it was worth it to post to HN as news, though. Perhaps I should start posting our achievements a bit more.
Like for example our Group Rides feature:
Re: OpenPGPjs has passed an independent security audit
#36I have zero trust in Proton after learning, that the free ProtonVPN service is provided by a data mining company from Eastern Europe[1]. [1] https://news.ycombinator.com/item?id=17258203 (please turn on "showdead" in settings, to see the entire thread)
Tesonet provides all kinds of services, like hosting, software development and cybersecurity for it's customers.
Re: OpenPGPjs has passed an independent security audit
#37Earlier quoted context omitted.
Yupp. My account at a particular website was terminated. They pointed to their TOS, where "anonymous" address are not allowed. Wasn't even given the chance to keep the account and change the email to an "acceptable" one.
What service? Name and shame.
Re: OpenPGPjs has passed an independent security audit
#38Not that it matters. They could silently replace it with a backdoored script and your browser would never tell you it happened. And to preempt the ProtonMail rep who is probably going to respond to this comment, I know that you can run the web app on localhost. But that doesn't mean that users who don't are any more secure.
The same can be said for any software that auto update (i.e. Chrome), no?
1. Most platforms these days require a signature with a key issued by the platform. In the browser you have HTTPS but that doesn’t help if the server is compromised.
2. It’s easier to target individuals (thus evading detection) if you’re serving the code to users directly (which I think is also the case with Chrome, but not Mac App Store, Linux package managers, etc)
3. Some platforms even do some amount of auditing before including software in their repositories.
Re: OpenPGPjs has passed an independent security audit
#39Earlier quoted context omitted.
Please, that's not a verified claim[0], and you shouldn't trust any VPN service that isn't operated by you in the first place. [0]: Plus, it was raised by a competitor, Private Internet Access, so it makes it even more difficult to get the facts straight.
> Please, that's not a verified claim[0], and you shouldn't trust any VPN service that isn't operated by you in the first place. The co-founders of ProtonMail were caught providing multiple inaccurate statements about their business practices in that thread, and couldn't deny any of the facts stated by the co-founder of PIA[1]. [1] https://news.ycombinator.com/item?id=17262566
Re: OpenPGPjs has passed an independent security audit
#40I have zero trust in Proton after learning, that the free ProtonVPN service is provided by a data mining company from Eastern Europe[1]. [1] https://news.ycombinator.com/item?id=17258203 (please turn on "showdead" in settings, to see the entire thread)
They explained it quite clearly: > We used Tesonet as a local partner before we had an official Lithuanian subsidiary, and rented office space from them. We don't share employees, infrastructure, etc. We have had a similar temporary arrangements with local companies when we opened offices in other jurisdictions where we didn't have an official presence yet. This type of arrangement is common in the startup world.
"For the latest project, Tesonet is working together with an international brand from Switzerland to create a security product that helps users protect their network traffic. As part of this technical partnership, we are collaborating on datacenter and network infrastructure that can easily supply 10 Gbps worth of bandwidth to users around the world. The product is developed using the latest authentication encryption methods and the best practices in the security world."
[1] https://web.archive.org/web/20180426161609/https://tesonet.c...