Earlier quoted context omitted.
Again, let me repeat this because you seem to be totally deaf: All I'm doing is defending use cases for the Web Crypto API. I'm not and have never defended this specific app. All I'm doing is pointing out that your wholesale dismissal of browser crypto is unwarranted. You're clearly just trolling me now because you've refused to answer any of my questions specific to the valid use cases of browser crypto and how ANY…
No, saying snarky things about crypto is my hobby , not my career. My career is actually breaking these stupid systems.
While I have your attention, could you take a look at this: http://substack.net/offline_decentralized_single_sign_on_in_...
BTW, there's enough of us idiots out there that we're not going to stop until we've figured this out! Being able to ship a decentralized version of say Facebook or Twitter that runs in the browser and allows people to manage their own private keys (aka, manage their own digital identity) is incredibly motivating. I don't trust platforms like iOS or Android to not shut down certain kinds of apps and I don't think my mother will ever be running an open-source OS on her tablet.
I have to say that I definitely lost my shit in this thread... and I'm sorry. I have a tendency to get emotional about this kind of stuff because the politics are a big part of what motivates me to build these kinds of things. I take these hard-lined stances against browser javascript as an assault on my principles for digital identity but also as a creative individual who strives for a positive and constructive environment.
That doesn't justify me calling people names. Especially if I'm going to be talking about the means not justifying the ends... ugh...
However, I do think that articles like this are very close to being out of date: http://matasano.com/articles/javascript-cryptography/
The Web Crypto API alleviates a number of these issues and novel uses of application caching manifests seem to solve the issue for good.
Check out this article, especially Gotcha #4. http://alistapart.com/article/application-cache-is-a-doucheb...
So in this case we've got an authoritative article that says "never ever far-future cache the manifest". And we've got an authoritative article that says "never ever do crypto in the browser".
Both articles take a pretty heavy handed approach and don't really set out to explore the deeper possibilities. They both kind of set out to create an environment where readers will also not question these principles for fear of being made look like a fool in front of their peers.
But the fundamental hacker ethos is to read articles like this and say "the intent of the APIs and authors be damned, I have other considerations!".
Anyways, I'd really appreciate your thoughts on this stuff... all of, including what I and a number of other people perceive as a toxic environment for creativity related to cryptography and infosec.