Skip to content

Comment on Age and Authenticated Encryptionparent

Comments

For me, it's about uploading files to the "cloud" such as Google Drive or Github and wanting to make sure that the data I uploaded is the same data that I am getting back. If the signatures fail I could unpack the file and manually review them to see what's up.

In your case, I think the problem is having backups that are attackable from production, and likely only having one set of backups.

You cannot just not use the backup

What would you do if instead of tampering with the backups or production they just deleted everything outright?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.