JavaScript Misdirection Contest #0

See http://misdirect.ion.land

HTML

<!-- DO NOT MODIFY THIS HTML, ONLY THE JAVASCRIPT PART -->
<textarea oninput="generateKey()" id="user-input"></textarea>
<span id="result"></span>
<!-- DO NOT MODIFY THIS HTML, ONLY THE JAVASCRIPT PART -->

CSS

/* DO NOT MODIFY THIS CSS, ONLY THE JAVASCRIPT PART */

JavaScript

/*

=== README.TXT ===
    While I know nothing about cryptography, I thought I'd have a crack at the misdirect.ion.land
contest.
    
    Officially, this entry works by hashing a string composed some user input, the time, and a salt
value. (See renderKey().) User input is read by generateKey(), and the time is just a call to
Date(). The salt value is a little more roundabout, but is ultimately just an array of the pixel 
values of a small image. PNG compression helps speed page load, but the transfer method is not very
important.
    
    Everything is legitimate, if misguided, except for line two of getHashKey(). Here, we
"accidentally" assign to s.src instead of hashing it for more randomness. This causes the browser 
to fetch the new image. This looks accidental because the new value is just our salt, which is 
random noise from the salt image. However, the salt image contains with almost* no misdirection the
ASCII values of the URL we will fetch. These are transformed by unbuffer() to a string, which is
then assigned to s.src. This loads the URL in the salt, appended by the user's random input, at the
time of generation, which gives us the information we need to recreate the key. The value is then
xor'd to hide the url for the rest of the function.
    
    I hope you enjoyed the entry, basic as it was. I'm sure you could work up something better with
getters and setters and shared typed array buffers, but I couldn't come up with any sort of
justification why any of that should be in a random key generator. You can find me at ddr0.ca. I'm
currently looking for part-time or contract work, remote or in Vancouver BC. Thanks for reading!
    
Footnote:
* The green channel is ignored via buf[i]&0xFF, so it is used to increase the innocent look of
  our image. (There's an ignored alpha channel too, but it's not in the source image.)

*/

window.generateKey = generateKey;
function generateKey(e) {
	var userRandom =...