Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

As all clients need a password to enter a room, the messages could be encrypted with that password. There are a lot of JS libraries that could do this, e.g. Triplesec



Author here. Right now, it's only as secure as https, but I'll look into JS encryption. It's just a fun project that came out of some Go experiments.


Still would only be as secure as https if the client is downloading your JS crypto lib every visit.


Would it be safe to keep the crypto lib on the client somehow? Browser addon? local storage? How would we do that?





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: