I’m trying to create a web app that involves sharing of user-generated content, but one of the goals is that the service host operator should be blind to the content. Only authorized users should be able to see the content shared with them. This implies the content must be encrypted at rest, and users must hold custody of their private signing key.

I figure the situation requires an open source browser extension to hold onto a user’s keys and decrypt content for them. The web app would still be able to browse all of the site’s metadata, but any plaintext content must be siloed in the extension. The reason for using an extension is that the source code would be open source and independently verifiable, while building the same functionality into the web app would require trusting the host to serve the code you expect.

Do you think that’s a reasonable tradeoff or is this asking too much from users?

The other option would be just requiring users to download an open source app for content viewing.

EDIT: Perhaps an important followup: are you OK placing trust in the host to never access your confidential data if it means you don’t have to install additional client software or worry about verifying that client software’s authenticity?

  • tatterdemalion@programming.devOP
    link
    fedilink
    arrow-up
    1
    ·
    1 day ago

    I’ve answered this question in many other threads at this point, but since you’re now the top comment:

    Proton Drive and Mail still require you to trust them to serve you Javascript that doesn’t snoop on your plaintext content. They don’t have any way of proving that their web app isn’t taking your plaintext emails (which you can read in your browser and therefore they are visible to Javascript on that page) and sending it back to their server.

    • lawks@aussie.zone
      link
      fedilink
      arrow-up
      1
      ·
      15 hours ago

      It seems that ignorance abounds in this post’s comments. People are apparently unaware that one can write an extension that has no more privileges than a normal web page, and unlike a page, the code cannot change on every load. Your idea is good. I’d recommend not using any minification or obfuscation in the extension, and keep it as brief as is possible, for maximum transparency.

      In a parallel situation, I’ve always been wary of hosted password managers’ web interfaces like those of Lastpass, 1Password, and even Bitwarden, because one has to accept the code served at every access is clean. Ultimately, one enters their master password/secret keys, as plain text, into a web page that’s difficult to audit & unlikely to be, on every view. Whereas offline/client-side encryption outside the transmission medium is far more trustworthy (e.g. KeePass).

    • blight@piefed.blahaj.zone
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 day ago

      Is their JS code open source? If so, I don’t see any real differences between an extension and JS code. Unless extensions have less privileges or something. The user will have to either trust the code or inspect it themselves regardless if it’s an extension or JS code.

      • vogi@piefed.social
        link
        fedilink
        English
        arrow-up
        1
        ·
        20 hours ago

        Just FYI: I think since manifest 3 or so you do need explicit permissions to access a sites HTML. And the end user can see which sites the extension has access to. Doesn’t make me install more extension than I really have to though.

      • HeHoXa@lemmy.zip
        link
        fedilink
        arrow-up
        1
        arrow-down
        1
        ·
        edit-2
        20 hours ago

        Extensions can have more access.

        They can snoop / manipulate across tabs or even scan the local drive and execute system commands… when given the access.

        I had to make one for work once to let a web app run a legacy command prompt system. The web app’s search was better, but the users wanted to edit with the old tool.

        It was kind of interesting the way it worked. Not remembering the full details, I created an extension and a batch script and had to register the batch script with a group policy and declare the extension’s permission to run that batch script

        Then the users could search a client in the web app and press a button to bring up their profile in the prompt app.

        Not a recommended approach for public facing apps.

        *Edit: No! It wasn’t a batch script… exactly… it was a C# app compiled to .dll that accepted client id as an argument

        • lawks@aussie.zone
          link
          fedilink
          arrow-up
          0
          ·
          15 hours ago

          When was the last time you wrote an extension? Long gone are the days when they could run system commands, and permissions must be declared in the manifest or they cannot be used, so if they aren’t in there, they’re not being used.

          • HeHoXa@lemmy.zip
            link
            fedilink
            arrow-up
            0
            ·
            15 hours ago

            … 3 years ago ish?

            I tried to clarify with the edit, you’re sorta right, it wasn’t a system command. It was “native messaging”

            But you’re sort of full of it too, as you can use this native messaging to execute arbitrary logic. Nobody said you don’t need a manifest, and someone did say you needed a group policy entry too

            • lawks@aussie.zone
              link
              fedilink
              arrow-up
              1
              ·
              15 hours ago

              I know what native messaging is, and I’m not “full of it” because native messaging does exactly nothing at all unless the user explicitly installs software at the system level to receive those messages and act upon them. If the user doesn’t know the difference between installing an extension in a browser and downloading & executing local programs, that’s an education problem, but having to do some separate installation step is a useful security obstacle. It’s much safer compared to old school extensions.

              Also, Firefox Quantum came out in 2017, which used the manifest permissions system (wasn’t Chrome ahead of them?), so the tech you were originally talking about is older than 9 years, not 3.

              • HeHoXa@lemmy.zip
                link
                fedilink
                arrow-up
                0
                arrow-down
                1
                ·
                15 hours ago

                💩 semantic distinctions, extensions can run whatever when you register the logic in advance, as suggested in my first comment

                • lawks@aussie.zone
                  link
                  fedilink
                  arrow-up
                  1
                  ·
                  15 hours ago

                  If you think installing a downloaded program alongside your browser is a “💩 semantic distinction” from a bit of script running inside your browsers sandboxing, then it’s clear you either don’t know what you’re talking about, or you’d rather continue to to spread FUD than concede on basic facts.

                  • HeHoXa@lemmy.zip
                    link
                    fedilink
                    arrow-up
                    0
                    arrow-down
                    2
                    ·
                    14 hours ago

                    It is he thing I suggested from the start.

                    I already get you’re full of it. You don’t have to jeep selling me

      • tatterdemalion@programming.devOP
        link
        fedilink
        arrow-up
        0
        ·
        1 day ago

        The difference is that JS code served by a web server can change at the server’s whim, and there is no standard way to verify that it matches what you expect except by reading it every time you visit the page.

        With an extension, assuming you trust the browser itself, you can check that the extension matches its source, and you only need to do that once per install.

        • blight@piefed.blahaj.zone
          link
          fedilink
          English
          arrow-up
          1
          ·
          24 hours ago

          That’s true. On the other hand, the extension gains a much larger attack surface since it has access to a lot more data (every site you visit vs. only the site that serves the JS code). At the end of the day, people wouldn’t use your site if they didn’t trust your site, especially if they use it for privacy and integrity reasons, so for most users I think JS is the better option. I suppose there’s no reason you can’t offer both though.