As for me and most normal users, the security we need is not from NSA type of snooping but from mid level risks.
Most users, disregarding the government for the moment, don't need encryption full stop. They don't send anything commercially sensitive that an attacker's going to be interested enough in to try to intercept their messages.
The use of encryption presupposes a motivated threat, and it's not clear to me that the NSA is significantly more powerful than other adversaries in that area. They've more computing power, more political power, they can buy zero day exploits. They probably even have some very smart people, who can find flaws faster than the attackers in civ-space. But speed isn't required, only persistence; motivation, interest. Which is, after all, what we're supposing in the first place if someone's going to go to the trouble of intercepting your messages.
It's not clear to me that unless your goal is 'make something that the NSA can't break into', you're going to make something that a well motivated attacker can't break into either. And this stuff only has to be broken once, then they'll just sell or share the attack. The conflict is asymmetrical.
Your argument seems to be posited on the idea that there will be no attacker; no-one anywhere, ever; sufficiently motivated to breach the protocol. And I find that highly questionable, given that a flaw has already been found - and with far lower levels of incentive than will be present if the system is widely deployed and used to protect valuable information.
Most users, disregarding the government for the moment, don't need encryption full stop.
You've no idea what you're talking about. Please stop spreading such bullshit around; other people might fall for it!
Fireship is an app that allows you to hijack the account of any user on the same Wi-Fi network as you are, if the network is not encrypted, and the user used a non-encrypted connection to the website. Facebook, Google, Twitter and Flicker were all susceptible to such attacks before the advent of this tool; afterwards, they fixed it by using https by default.
Do you want random strangers to have full access to your Facebook account? No? Then you should realize that most people do need encryption full stop.
Also, only very powerful attackers can hack https encryption (they need either access to your laptop (hardware access, or a zero-day exploit), or access to the website (e.g. court warrant, or coercing a certificate authority)).
We were having a discussion about Telegram and similar uses of encryption, a discussion where I specifically responded to a remark on the strength required of Telegram-style encryption. I would hope that most people are capable of interpreting the context of a remark - especially embedded in paragraphs that expand on it. Rather than, 'fall[ing] for it!'
-sigh-
Beyond that I'm not going to engage with you any further, on this or any other point. You strike me as a bully, restrained where you are simply by the absence of an excuse rather than the presence of decency. As such, I've no interest in associating with you.
Comments
Most users, disregarding the government for the moment, don't need encryption full stop. They don't send anything commercially sensitive that an attacker's going to be interested enough in to try to intercept their messages.
The use of encryption presupposes a motivated threat, and it's not clear to me that the NSA is significantly more powerful than other adversaries in that area. They've more computing power, more political power, they can buy zero day exploits. They probably even have some very smart people, who can find flaws faster than the attackers in civ-space. But speed isn't required, only persistence; motivation, interest. Which is, after all, what we're supposing in the first place if someone's going to go to the trouble of intercepting your messages.
It's not clear to me that unless your goal is 'make something that the NSA can't break into', you're going to make something that a well motivated attacker can't break into either. And this stuff only has to be broken once, then they'll just sell or share the attack. The conflict is asymmetrical.
Your argument seems to be posited on the idea that there will be no attacker; no-one anywhere, ever; sufficiently motivated to breach the protocol. And I find that highly questionable, given that a flaw has already been found - and with far lower levels of incentive than will be present if the system is widely deployed and used to protect valuable information.
You've no idea what you're talking about. Please stop spreading such bullshit around; other people might fall for it!
Fireship is an app that allows you to hijack the account of any user on the same Wi-Fi network as you are, if the network is not encrypted, and the user used a non-encrypted connection to the website. Facebook, Google, Twitter and Flicker were all susceptible to such attacks before the advent of this tool; afterwards, they fixed it by using https by default.
Do you want random strangers to have full access to your Facebook account? No? Then you should realize that most people do need encryption full stop.
Also, only very powerful attackers can hack https encryption (they need either access to your laptop (hardware access, or a zero-day exploit), or access to the website (e.g. court warrant, or coercing a certificate authority)).
We were having a discussion about Telegram and similar uses of encryption, a discussion where I specifically responded to a remark on the strength required of Telegram-style encryption. I would hope that most people are capable of interpreting the context of a remark - especially embedded in paragraphs that expand on it. Rather than, 'fall[ing] for it!'
-sigh-
Beyond that I'm not going to engage with you any further, on this or any other point. You strike me as a bully, restrained where you are simply by the absence of an excuse rather than the presence of decency. As such, I've no interest in associating with you.
Yeah, I probably overreacted.