"JavaScript cryptography considered harmful", a Matasano Security post

53 views
Skip to first unread message

Timothee Boucher

unread,
Aug 29, 2011, 2:00:48 AM8/29/11
to unhosted
Hello,

I figure this would be of interest for this list:
http://www.matasano.com/articles/javascript-cryptography/
with the associated Hacker News discussion:
http://news.ycombinator.com/item?id=2935220

I'm not saying it questions the encryption in Unhosted or anything
like that. Just that it's of interest :)
FYI, tptacek, the author of this post and co-founder of Matasano
Security, is a long-time HN user and is generally the "local"
reference when it comes to security and encryption.

Cheers,

Tim

Thad Guidry

unread,
Aug 29, 2011, 10:05:08 AM8/29/11
to unho...@googlegroups.com
It is better to showcase what the real problems are generally, for
unhosted and others, going forward with an eye towards security:

OWASP Top 10 Security vulnerabilities:
https://www.owasp.org/index.php/Top_10_2010-Main

An example of a web framework that is resistant to many of those and how:
http://seventhings.liftweb.net/security
http://www.assembla.com/wiki/show/liftweb

--
-Thad
http://www.freebase.com/view/en/thad_guidry

Reply all
Reply to author
Forward
0 new messages