Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So to frame the question in this light, the parties exchanging encrypted messages via javascript (on top of SSL) trust that they're doing everything in their power to maintain the integrity of their systems. Do they increase the surface area where attacks could take place? Sure. But in what way is sending encrypted messages on top of SSL any less secure than sending unencrypted messages on top of SSL.

One argument seems to be that there's no need for the added layer on top of SSL. Then I would ask, so why have passwords at all? After all it's guaranteed that the communications are secure. It looks like the disconnect here is that encrypted messages on top of SSL are behaving as a mechanism to help authenticate the recipient of the messages, like a password, and not trying to act in the same way that SSL behaves as a way to secure communications between 2 parties.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: