On Tue, Jul 22, 2014 at 4:38 PM, Aymeric Vitte <[email protected]>
wrote:

> And checking what is doing a 400 kB js code is trivial for any serious js
> dev


This assertion is completely ludicrous, especially when you're talking
about trying to find a potentially stealthy malicious payload in 400kB of
code. JavaScript benefits confusers and enables all sorts of obfuscation
techniques which can't be easily undone through simple static analysis.

Asking every user to verify the integrity of 400kB of JavaScript code by
manual review and searching for backdoors is a complete nonstarter when it
comes to practical solutions to detecting compromise.

TweetNaCl, by comparison, fits in 100 tweets.

-- 
Tony Arcieri
-- 
Liberationtech is public & archives are searchable on Google. Violations of 
list guidelines will get you moderated: 
https://mailman.stanford.edu/mailman/listinfo/liberationtech. Unsubscribe, 
change to digest, or change password by emailing moderator at 
[email protected].

Reply via email to