Linked by snydeq on Tue 16th Aug 2011 16:46 UTC
Permalink for comment 485392
To read all comments associated with this story, please click here.
To read all comments associated with this story, please click here.
Features
Linked by David Adams on 05/16/13 4:23 UTC
Linked by Thom Holwerda on 05/11/13 21:41 UTC
Linked by Thom Holwerda on 05/08/13 14:22 UTC
Linked by Thom Holwerda on 05/02/13 15:28 UTC
Linked by Thom Holwerda on 04/29/13 21:06 UTC
Linked by Thom Holwerda on 04/24/13 22:24 UTC
Linked by Thom Holwerda on 04/18/13 11:21 UTC
Linked by Thom Holwerda on 04/16/13 9:29 UTC
Linked by Thom Holwerda on 04/15/13 22:44 UTC
Linked by Thom Holwerda on 04/14/13 18:22 UTC, submitted by MOS6510
More Features »
Sponsored Links



Member since:
2006-07-26
They're basically saying HTML5 is insecure because javascript is plaintext.
This has to do with the program design and not the choice of HTML for the implementation.
They use Facebook and GPS location as an example.
In the end, you're relying on the phone to tell the truth. This is true whether it goes through a Javascript layer or is programmed natively. These things can be spoofed at a hardware, OS or driver layer upstream or the communications layers downstream.
If these locations need to be relied upon you need to control the entire stack beginning with tamper-proof hardware strapped to someone's ankle. Things which you cannot control, say cellular communications, need to be encrypted and the locations need to be signed.
And even then, you need to make sure that the person's foot is still attached ;-)