|
|
|
|
|
by smcgregor
4455 days ago
|
|
I don't think CryptoCat has been distributed as a traditional web app for at least a year (probably more). The browser code is distributed as an extension, which does not have the properties you describe. edit for sub-comment: A traditional web app updates every time you hit the URL. In a browser extension your code is not necessarily tied to any remote origin, including the Chrome/Firefox stores. It is a user's choice to automatically receive updates from the vendor and this is the same choice that you make if you use apt-get vs manual download/checksum/sig check/audit. |
|
Actually, browser extensions have the exact same properties except for being code signed. That's not enough: http://arstechnica.com/security/2014/01/malware-vendors-buy-...
> I don't think CryptoCat has been distributed as a traditional web app for at least a year (probably more).
That they ever shipped in-browser crypto demonstrates that they shouldn't be shipping crypto.