|
|
|
|
|
by bren2013
4387 days ago
|
|
This is also precisely the problem I was trying to avoid by introducing formality. Is it like saying that a tank made of paper sheets is insecure, or is it like saying that a heavily-armored tank is insecure (against a nuclear weapon)? It is never okay to omit important information like the threat model in cryptography. That information is essential to the system's analysis. |
|
Yes, I'd say it's more like that one. The technology is insecure against threat models it is almost certain to face.
> or is it like saying that a heavily-armored tank is insecure (against a nuclear weapon)?
No, I don't think it's like that one. A tank could realistically participate in a nuclear conflict, but that's not necessarily what a tank is intended for. Whereas, JS crypto is presumably intended to protect users when the remote server can't be trusted. (What else would it be for?) It can't offer such protection.