The browser can perform cryptographic operations, but page code and its loaded dependencies execute in the same origin as the protected workflow. Encryption changes who can read stored bytes; it does not replace server authorization, transport protection, or defense against compromised page code. This track follows a local case-note draft that must be unreadable from a copied storage record while its reviewer is signed out. It covers key custody, authenticated encryption, password-based unlock, and rotation. Every design states what happens after device loss, account switch, or key compromise.
Topics in this track
- Browser Encryption Threat Model and Key Custody — Decide what copied storage bytes should resist and who can still use the decryption key.
- Authenticated Encryption, Nonce, and Record Binding — Encrypt a draft with a fresh nonce and bind its ciphertext to the intended record metadata.
- Password Unlock, Derivation, and Recovery — Derive an unlock key with recorded parameters and make forgotten-secret behavior explicit.
- Key Rotation, Envelopes, and Device Loss — Re-encrypt local records under a new key without losing drafts or overstating revocation.
Prerequisite paths
Browser Security and Data Stewardship; Data Retention, Export, and Erasure.
Neighbor track
Offline Storage and Upgrade Safety.
Practice path
Build Project: encrypted local draft lifecycle and check decisions in Web Development: offline and browser-key decisions quiz.
