----- Original Message ----- > From: "Nico Williams" <nico@cryptonector.com> > To: "Anders Rundgren" <anders.rundgren@telia.com> > Cc: "Brian Smith" <bsmith@mozilla.com>, public-web-security@w3.org, "Jarred Nicholls" <jarred@sencha.com>, "David > Dahl" <ddahl@mozilla.com> > Sent: Friday, June 10, 2011 3:33:46 PM > Subject: Re: Smart Card support. Re: Request for feedback: DOMCrypt API proposal > Of course, the serve could do all that on the server side just as > well. But I think there's benefits to doing profile > decryption/encryption on the client side. Indeed, user profile data on servers could literally just be an email address, a hashed password and a blob (or not, maybe the blob is in localStorage), freeing the business of the fallout when the server is compromised. Cheers, DavidReceived on Friday, 10 June 2011 20:50:44 GMT
This archive was generated by hypermail 2.2.0+W3C-0.50 : Friday, 10 June 2011 20:50:44 GMT