Hacker News new | ask | show | jobs
by automatthew 4613 days ago
The problem isn't only with primitives, as I think you've mentioned before. Even assuming a browser provides turnkey symmetric crypto for arbitrary plaintext lengths, "content-controlled JavaScript" can still subvert the ostensible encryptions in subtle ways.