D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] Thoughts on crypto engineering

 

On Tue, 10 Sep 2013, bad apple wrote:
Can anyone spot the amusingly appropriate modifier to the straw
man argument?

Apparently not. Care to enlighten us?

Presumably the 'random' in 'randomly tag software companies'.

It's good practise in cryptography not to trust anyone. This means that you shouldn't trust anyone less, as doing so implies you trust others more.

Of course, that's the theory. In practise you have to make trust decisions all the time, depending on the context and on your personal views. Recent event have shown that if your threat model includes the NSA, you can't even trust open source or open standards. So you're pretty much stuffed, unless you're one of the very few people who can write their own crypto libraries.

Martijn.


--
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq