Alex Rivera | Logout

What are the valid use cases for client side encryption?

Asked 2011-08-19T15:01:31.343
12

I just read about the Stanford Javascript Crypto Library (jsfiddle example) which supports SHA256, AES, and other standard encryption schemes entirely in javascript. The library seems very nifty, but I don't know of a reasonable use case for it.

As some questions have already pointed out, client side encryption is not a safe way to pass secure data to a server. HTTPS should be used instead. So, are there any projects that would benefit from or require client side encryption?

Edit
Report

1 Answer

3

Like anything on the client, you can use obfuscation to make things more difficult for casual users to peek inside, but since the client would also need to have a copy of the decryptor there's nothing to stop the user from using the decryptor themselves either.

JavaScript is an insecure environment, period.

answered 2011-08-19T15:06:25.827

Your Answer