|
I mean, it is secure against passive adversaries... but that's nit-picking. ChatCrypt has made a large number of mistakes, though, I concur. They don't use HTTPS, it isn't open sourced, and the developer is practically anonymous. I would still maintain that Matasano's article is problematic, though, because it has one of two effects on the reader: 1. The reader is more-than-well convinced on faulty basis that JS crypto should never be used. 2. The reader is still adamant on continuing their project, but is now alienated from a source that could have offered a plethora of helpful advice. (Example: "Please, for all that is good, use HTTPS.") Of course, nothing will prevent the occasional surfacing of bad crypto, but their article certainly doesn't help any of its causes. |