Hacker News new | ask | show | jobs
by notwhyships 4616 days ago
This is a deck by Ben Adida (formerly of Mozilla, where he led the Persona project and now at Square) explaining how that argument is reductionistic. https://docs.google.com/presentation/d/1bLBb0EIJ0cuoAhsmI1XL...
1 comments

Can you please help me find even an argument in that deck, let alone any refutation? Did I get an incomplete deck, perhaps? The version I'm seeing stops at slide 22.
There are 22 slides.

It's admittedly terse (it was part of a presentation Ben Adida gave at the first Real World Cryptography workshop).

However, I'd suggest reading the deck again, and while you do asking yourself, does JS crypto provide any security beyond what SSL does? And, can JS crypto make sense as part of a defense in depth/layered security approach?

He's presumably referring to slides 17-20. It essentially boils down to "JS crypto in the browser is better than nothing".
But it's not — at least not necessarily. That's the problem. It creates a potentially incredibly dangerous false sense of security, and nothing in the deck refutes that, or even argues against it.