I wish something like this would take off - https://github.com/kylehuff/webpg-chrome We deserve a better userspace from our browsers. The excuse that "users" don't want this because its "hard" is circular.
The project looks really cool! But...the fact that the website has a certificate error doesn't inspire much confidence. Especially since it's a security tool. :(
OpenPGPjs v3.0
21–30 of 46 posts
Re: OpenPGPjs v3.0
#22What is the threat model for PGP in JS? Like, is there an Alice, Bob, Carol, Eve story under which PGP in JS makes sense? The canonical example that IMO doesn't make sense is when Alice and Bob want to communicate privately using Eve as an webmail provider who wants to snoop in on the communications. Alice and Bob can't just trust Eve to provide a copy of OpenPGPjs in a tag on EveMail.com, because then they're trusti…
I've been looking for gmail alternatives and this is my conclusion. Protonmail plays the part of the secure and private email provider, but, technologically, can't provide that. The only concrete thing their users have going is the superior legal environment of Switzerland. A less-than-concrete comforter is that if we believe that the people behind Protonmail believe in privacy, we'll tend to think they're more likel…
Re: OpenPGPjs v3.0
#23Earlier quoted context omitted.
> In case anyone that doesn't follow the development of the library closely missed it, the main improvement in this version is the introduction of ECC support. Wow...I'm sort of shocked that wasn't a v1.0 consideration. > ECC tends to be able to provide equivalent levels of security as traditional "big prime" cryptography (like RSA) with less computationally intensive operations. This is especially important in a lib…
Aren't there multiple operating quantum computers right now? Isn't this a very imminent problem?
Re: OpenPGPjs v3.0
#24Earlier quoted context omitted.
The project looks really cool! But...the fact that the website has a certificate error doesn't inspire much confidence. Especially since it's a security tool. :(
What certificate error? Neither https://openpgpjs.org nor the link here have a certificate error for me. Maybe you are being MITMed...
Re: OpenPGPjs v3.0
#25Earlier quoted context omitted.
The project looks really cool! But...the fact that the website has a certificate error doesn't inspire much confidence. Especially since it's a security tool. :(
What certificate error? Neither https://openpgpjs.org nor the link here have a certificate error for me. Maybe you are being MITMed...
Re: OpenPGPjs v3.0
#26Earlier quoted context omitted.
The project looks really cool! But...the fact that the website has a certificate error doesn't inspire much confidence. Especially since it's a security tool. :(
What certificate error? Neither https://openpgpjs.org nor the link here have a certificate error for me. Maybe you are being MITMed...
Re: OpenPGPjs v3.0
#27Earlier quoted context omitted.
> In case anyone that doesn't follow the development of the library closely missed it, the main improvement in this version is the introduction of ECC support. Wow...I'm sort of shocked that wasn't a v1.0 consideration. > ECC tends to be able to provide equivalent levels of security as traditional "big prime" cryptography (like RSA) with less computationally intensive operations. This is especially important in a lib…
Aren't there multiple operating quantum computers right now? Isn't this a very imminent problem?
It's not clear whether we can currently create a machine with sufficient logical qubits to run Shor's algorithm in a meaningful way.
However, out of an abundance of caution, we're "starting" now (some designs have existed for longer but this (NIST PQC) is the first competition, which focuses minds) so as to have something ready when/if a quantum computer becomes a reality.
Re: OpenPGPjs v3.0
#28I wish something like this would take off - https://github.com/kylehuff/webpg-chrome We deserve a better userspace from our browsers. The excuse that "users" don't want this because its "hard" is circular.
The project looks really cool! But...the fact that the website has a certificate error doesn't inspire much confidence. Especially since it's a security tool. :(
No data is lost or stolen. Customers won't like it, you may lose sales, etc, but your data security is fine.
Re: OpenPGPjs v3.0
#29Earlier quoted context omitted.
What certificate error? Neither https://openpgpjs.org nor the link here have a certificate error for me. Maybe you are being MITMed...
I'm also getting it. The certificate for https://webpg.org/ expired October 29, 2017.
Re: OpenPGPjs v3.0
#30Earlier quoted context omitted.
The project looks really cool! But...the fact that the website has a certificate error doesn't inspire much confidence. Especially since it's a security tool. :(
Expired certificate is probably the least egregious security error, especially for a homepage. No data is lost or stolen. Customers won't like it, you may lose sales, etc, but your data security is fine.