Developer Offshore research
What happens to a Web Crypto key across browser workers?
· Research report
A small, reproducible study of one browser-origin test matrix using declared key algorithms, extractability settings, and worker types. The report separates observed behavior from inference and records what the test cannot establish.
Use this report with the Research library and the related daily developer guides to turn evidence into a bounded work brief.
Key Stats
- 1 declared unit of analysis
- 7 recorded signal classes
- 2 mechanism-specific primary references
Key Takeaways
- Capture algorithm, extractable flag, usages, clone result, operation result, exception name, and browser version.
- Check the competing explanation that successful structured cloning does not imply that raw key material became exportable.
- Treat the finding as local to the recorded revision, workload, environment, and observation window.
Research question and scope
The question is: What happens to a Web Crypto key across browser workers? The unit of analysis is one browser-origin test matrix using declared key algorithms, extractability settings, and worker types. The protocol fixes the code revision, configuration, workload, identities, and observation window before a run begins.
Method
Create baseline, boundary, repeated, interrupted, and recovery runs with synthetic data. Record algorithm, extractable flag, usages, clone result, operation result, exception name, and browser version. Preserve raw output before adding notes, identify the clock behind each timestamp, and repeat the closest passing run after every isolated change.
How the sources inform the protocol
W3C Web Cryptography API defines the main mechanism used in the test. MDN: CryptoKey provides a second standards or implementation view. They determine what the fixtures should exercise, but neither source proves how this particular system behaves.
Counterevidence and inference limits
Try to overturn the first explanation by testing whether successful structured cloning does not imply that raw key material became exportable. Change identity, timing, failure state, and load separately. A correlation between two signals is not a causal result unless the controlled runs exclude the credible alternatives recorded here.
Ownership and review
A Philippines-based offshore developer may build fixtures, run approved experiments, add focused instrumentation, and prepare a reversible patch. Internal data, security, platform, and release owners control sensitive access, production action, exceptions, and acceptance of remaining risk.
Limitations
This study covers only one browser-origin test matrix using declared key algorithms, extractability settings, and worker types. It does not represent every client version, dependency delay, historical record, regional path, or future workload. The report must list missing cases, measurement uncertainty, failed runs, and the observation that would change the conclusion.
Evidence table
| Signal | What to inspect | Owner |
|---|---|---|
| Outcome | Acceptance evidence for the bounded task | Task reviewer |
| Control | Access, test, and approval boundary | Internal owner |
| Handoff | Open risks and next decision | Next owner |
Good distributed work is observable at the handoff: the result, evidence, limitations, and next owner are all explicit.
Frequently asked questions
Does the result apply to the whole platform?
No. It applies to the declared unit, revision, workload, environment, and observation window.
Who approves a production change based on this study?
The accountable internal owner reviews the raw evidence, inference limits, and remaining risk before authorizing production action.