Hacker News new | ask | show | jobs
by fooyc 4664 days ago
If your browser is untrusted, you are doomed.

> Furthermore, this helps against content disclosure if the server is compromised.

If the server is compromised, openpgp.js is compromised too.

1 comments

Presuming the private key for the messages is not on the server, then old messages will not be compromised.

A kind of perfect secrecy for messages.

No need to do this on the client side then (that was my point)
You could do the exact same thing on the server, but that's using server's CPU instead of clients?
yeah its often called perfect forward secrecy - PFS - too.

http://en.wikipedia.org/wiki/Perfect_forward_secrecy