159
submitted 4 months ago* (last edited 4 months ago) by sag@lemm.ee to c/opensource@lemmy.ml
you are viewing a single comment's thread
view the rest of the comments
[-] elliot_crane@lemmy.world 9 points 4 months ago

This seems like a cool idea, but also somewhat questionable from a security standpoint? Isn’t distributing the encrypted content alongside the means to decrypt it (i.e. bundling this all in one file which is sent to the client) essentially equivalent to providing physical access to an encrypted drive? Like an attacker with enough time and effort could bypass the encryption.

[-] Mike1576218@lemmy.ml 10 points 4 months ago

It is not a problem to distribute the decryption algorithm. The question remains against what this will protect. Normal https encrypts the traffic safely during transit. With this, the data is also encrypted on the server. But if you can access the server, you can modify the javascript code to send the password back to a server.

It could be used on something like IPFS, where all data is basically public but you can be sure it hasn't been modified.

[-] CosmicTurtle0@lemmy.dbzer0.com 7 points 4 months ago

Exactly. This shouldn't be used to store your taxes, for example. But it might be good if you want to post details about your baby shower without your parents getting the details.

[-] elliot_crane@lemmy.world 3 points 4 months ago

Yep, definitely situational depending on your risk model/tolerance; pretty cool idea nonetheless.

this post was submitted on 31 Aug 2024
159 points (100.0% liked)

Open Source

32240 readers
318 users here now

All about open source! Feel free to ask questions, and share news, and interesting stuff!

Useful Links

Rules

Related Communities

Community icon from opensource.org, but we are not affiliated with them.

founded 5 years ago
MODERATORS