HN user

kingzero

14 karma
Posts1
Comments6
View on HN

Can we recognize that this is a good first step, and definitely constitutes a huge improvement over gmail/yahoo type webmail solutions?

No its not. "Browser crypto" in the form of JS is broken. There are many different possible attacks. So a false sense of security is actually worse then no security at all.

Same here. So i checked what ciphersuits they use.

TLS_RSA_WITH_RC4_128_SHA

Too bad they cant correctly set up their servers ...

No, as explained in the writeup, the server stores your private key encrypted with your passphrase. The server never sees your passphrase, or your private key.

The only place a private key belongs to is the users machine (preferably somewhere without internet access).

As mentioned in the writeup, there's a beautiful way you can protect even non-power-users. Because the extension downloads and verifies the webapp HTML, CSS and JS every time it runs, the web app is constantly being validated.

Imagine the following. An Attacker manages to hijack your server. They fingerprint[1] the browsers of each user and only send malicious JS to certain users that dont use your extension. No one will ever know, that they have been compromised.

[1] https://panopticlick.eff.org/browser-uniqueness.pdf