Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

SJCL is good software and has good defaults for its high-level encrypt function `sjcl.json.encrypt`. It uses CCM so you don't have to MAC in addition to encrypting (as TripleSec does). Depending on what parameters and degree of safety you want for PBKDF2, you might wind up locking up the browser while your keys are being derived. It's hard to speed up this part of the encryption process because it's meant to be intentionally slow to prevent password cracking.

The biggest problem you'll have in building a secure chat app is establishing the connection in the first place. To do that, either the participants will have to share a secret, or there will have to be some sort of public-key based handshakes with certified public keys.



CCM is short for "Counter with CBC-MAC". I does also MAC the encrypted data and is equally slow as using a cipher and HMAC on top of it. A real speed improvement would be the Galois Counter Mode.


In my experience, speed isn't an issue. The only slow part of any of this is PBKDF2, unless you're dealing with huge files (not the case in chat).




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: