|
|
|
|
|
by djjaxe
4603 days ago
|
|
Wouldn't Lavabit be better if all decryption was done on client side, either with javascript or a client side add-on/extension? This way the only thing that is ever on the server is the public key? The only thing left would be if it had been in a man-in-the-middle attack... which is always an issue on the internet unless every part is encrypted which is hard to do... though internally it could potentially be safe as it would not ever be sending out of itself and emails being sent would also be encrypted client side using javascript/add-on/extension...
(also have the keys generated on client side)
yes this would inevitably be a large client side program but for security it would be worth it. |
|
There doesn't seem to be any serious alternatives to thick, open-source, locally installed clients. As a web affectionado and JavaScript nerd, this pains me too, but we'll have to get used to it.