Why Don’t You Use Public Key Encryption To Protect Your Data Sent From the Browser?

--

I recently asked a software developer why they didn’t encrypt sensitive data back to the back-end application. “Well, we use https, so it’s okay”. “But, before we get to the tunnel, and after it, anyone and anything can read the data. How can you know it is a trusted API you are dealing with?”. “Well, it’s not my problem, it’s up to https to do…

--

--

Prof Bill Buchanan OBE FRSE
ASecuritySite: When Bob Met Alice

Professor of Cryptography. Serial innovator. Believer in fairness, justice & freedom. Based in Edinburgh. Old World Breaker. New World Creator. Building trust.