W3C home > Mailing lists > Public > public-identity@w3.org > February 2012

Re: Charter and the NetFlix UC

From: Ron Garret <ron@flownet.com>
Date: Fri, 17 Feb 2012 11:00:06 -0800
Cc: public-identity@w3.org
Message-Id: <3AF78C3E-457F-4E78-BFBE-493E434D5C94@flownet.com>
To: Anders Rundgren <anders.rundgren@telia.com>

On Feb 17, 2012, at 10:43 AM, Anders Rundgren wrote:

> On 2012-02-17 19:19, Ron Garret wrote:
>> On Feb 17, 2012, at 4:52 AM, Anders Rundgren wrote:
>>> I would personally have started with naive questions such as
>>>     "What's wrong with signText?"
>> For starters, it's not documented anywhere that I could find. 
> Eh? I explicitly referred to the 1996 version:
> https://developer.mozilla.org/en/JavaScript_crypto

Yes, I looked at that page.  The only occurrence of the string "signtext" on that page is this:

DOMString signText(DOMString stringToSign,
                   DOMString caOption /* ... */);

And the only occurrence of the string "caOption" is in that excerpt as well.  That is not what I would consider adequate documentation.

> Poorly documented but actually used and even requested:
> http://www.google.az/support/forum/p/Chrome/thread?tid=3506388787b6fb7d&hl=en

Look, you asked what was wrong with signText.  That it is "poorly document" is one of the things that is (currently) wrong with it.  The problem is not that it is impossible to do crypto in Javascript.  Javascript is after all a Turing-complete language.  The problem is that it is (currently) *hard* to do crypto in Javascript.  And signText does not (currently) make it any easier, partly because it is not (currently) adequately documented.

It is possible that the solution to all our problems is simply to document signText.  I doubt it, but if you disagree the way to resolve the dispute is not to argue about it but to go write some documentation.

Received on Friday, 17 February 2012 19:00:37 UTC

This archive was generated by hypermail 2.4.0 : Friday, 17 January 2020 16:09:07 UTC