Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There doesn't appear to be much crypto in this project; it's a small application built on SpiderOak's Crypton.io. I'm not a fan of Crypton, but it's not clownshoes crypto.

Just to be clear to everyone on the thread: it's very unlikely that there's anything practical an attacker can do with the modulus bias in a situation like this.



> Just to be clear to everyone on the thread: it's very unlikely that there's anything practical an attacker can do with the modulus bias in a situation like this.

Correct. This was just the first thing I saw in a cursory glance through their app.js file.

I haven't reviewed Crypton.io and can't say whether I like it or not. What don't you like about it in particular?


> I'm not a fan of Crypton

Just curious - is this to do with using javascript crypto[0]? or something that goes beyond that?

[0] https://www.nccgroup.trust/us/about-us/newsroom-and-events/b...


JavaScript is only a real issue when you have an insecure code delivery mechanism. The article spells that out pretty well.


Yes, I understand. I was wondering why tptacek wasn't a fan though, and the only reason I could think of was that it might encourage this usage?? even though it looks like they explicitly discourage this[0]. It's the first time I hear of crypton.io - so just trying to learn more.

[0] https://crypton.io/docs/




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: