Hacker News new | ask | show | jobs
by eliaskg 4089 days ago
As all clients need a password to enter a room, the messages could be encrypted with that password. There are a lot of JS libraries that could do this, e.g. Triplesec
2 comments

Author here. Right now, it's only as secure as https, but I'll look into JS encryption. It's just a fun project that came out of some Go experiments.
Still would only be as secure as https if the client is downloading your JS crypto lib every visit.
Would it be safe to keep the crypto lib on the client somehow? Browser addon? local storage? How would we do that?