> They also implemented AES with S-boxes in pure JavaScript (no bitslicing), which adds a cache-timing leak. Yay.<p>From the DEKRA security review certificate [1]: "Proven implementations of cryptographic primitives." is marked as a pass... (I also couldn't find a way to verify the authenticity of this certificate).<p>[1] <a href="https://appdefensealliance.dev/reports/com.mess.engerx_1717934792836666.pdf" rel="nofollow">https://appdefensealliance.dev/reports/com.mess.engerx_17179...</a>