|
|
|
|
|
by nly
4669 days ago
|
|
This didn't need proving. They send you JavaScript code, which you trust to encrypt your files. Without a built-in, well-audited, static browser mechanism no web service can ever be trusted with confidential data. If the Feds decide to raid MEGA again they can simply modify their server side script to recognise your IP and serve you bad JavaScript from the MEGA domain, revealing your keys the next time you login. Nobody would be any the wiser. Personally I'm waiting for JS crypto to take off big time and idiots to start using it from a CDN. |
|
That's why mega has a separate app: https://mega.co.nz/#chrome