Skip to content
AITroveRead. Build. Understand.

Browser Cryptography and Key Custody

Use browser cryptography only with a stated threat model, unique nonces, and a workable key-recovery policy.

The browser can perform cryptographic operations, but page code and its loaded dependencies execute in the same origin as the protected workflow. Encryption changes who can read stored bytes; it does not replace server authorization, transport protection, or defense against compromised page code. This track follows a local case-note draft that must be unreadable from a copied storage record while its reviewer is signed out. It covers key custody, authenticated encryption, password-based unlock, and rotation. Every design states what happens after device loss, account switch, or key compromise.

Topics in this track

Prerequisite paths

Browser Security and Data Stewardship; Data Retention, Export, and Erasure.

Neighbor track

Offline Storage and Upgrade Safety.

Practice path

Build Project: encrypted local draft lifecycle and check decisions in Web Development: offline and browser-key decisions quiz.

Curriculum

Storage details