On Cloudflare’s blog, a senior research engineer shares a plan for “improving the trustworthiness of JavaScript on the web.”
“It is as true today as it was in 2011 that Javascript cryptography is Considered Harmful.”
The main problem is code distribution. Consider an end-to-end-encrypted messaging web application. The application generates cryptographic keys in the client’s browser that lets users view and send end-to-end encrypted messages to each other. If the application is…








