ietf-wg-scitt / draft-ietf-scitt-software-use-cases

Other
0 stars 5 forks source link

Web content/web applications #8

Open simon-friedberger opened 9 months ago

simon-friedberger commented 9 months ago

Reasonable security for e2e encryption in the browser requires verifying that web applications which are using cryptographic APIs and plaintexts have not been modified. While this seems to be covered by the architecture it might be worth adding an example to ensure that everything is in place. There is related w3c work starting in this repository.

SteveLasker commented 8 months ago

Hi @simon-friedberger, This would be a great addition to the user-cases. Would you like to make this into a PR?

SteveLasker commented 7 months ago

@simon-friedberger, we've started a scitt-examples repo to iterate on these types of scenarios.

If the writing the examples surfaces gaps in the existing use-cases, that would be great to re-consider and add more details. We'll leave open, pending the addition of some examples. Thanks, @simon-friedberger