"Guru" is probably the right word to use for Schneier at this point, and here's another great example of him inserting himself into a story he has no involvement in, making comments that betray a complete lack of awareness of the context of the story he's commenting on. Par, unfortunately, for the course.
It is doubtless the case that Schneier is fielding constant phone calls from trade reporters asking for his opinions on the security news of the day. Taking those calls, and writing the op-ed-style pieces that generate them, is probably the bulk of his job description. And so it's to be expected that he's going to be asked questions about things like Chrome's "virus-proofness", and having given no thought to Chrome or its architecture, be at a loss for pithy commentary. Hence, "2+2=3". Thanks, Bruce.
But before you feel too much sympathy for him, remember that he always has the ability to tell the reporter, "sorry, I don't know enough to comment intelligently on this story".
You've been interviewed by a reporter, yes? His very next sentence could have been something like, "It's not going to be virus-proof, but I'm glad to see they're thinking about security early. There is still a lot that can be done at the operating system level to improve security for the user."
The reporter would have cut that part out. It's not controversial enough. You could do the same thing with his blog post on homomorphic encryption if you took the phrases, "Gentry’s scheme is completely impractical," and "I think he’s being optimistic with even this most simple of examples," in isolation from "practicality be damned -- this is an amazing piece of work," and "I never expected to see one [a secure fully homomorphic cryptosystem]."
I don't understand this need to pull Schneier down. He's a smart guy, most of his writing is good, and he helped design a cipher that came pretty close to being selected for AES. Anyone who enters the media game is going to end up getting a bit caricatured.
You'll note that I didn't comment on his post about Gentry's homomorphic encryption scheme, for two reasons: (1) homomorphic encryption is a very boring topic, and (2) I don't feel like I have an authoritative argument for Schneier not being qualified to talk about it. Having dispensed with the straw man in your second graf, I'll take the 1st and 3rd in order.
I have been interviewed by reporters. And I have, in fact, made lots of mistakes with them. Security researchers are unnaturally attractive to trade reporters, and there's business value in cultivating contacts with them, and I've definitely let that process run too far in the past.
So, a mistake is a mistake. And thus, regarding your first graf, two responses:
(1) I stand by my original argument that Schneier doesn't appear to be close enough to Chrome OS security to comment on it, and his comments appear to misconstrue what Chrome OS is aiming for, and
(2) I stand by my original argument that this is an example of Schneier's business objective of inserting himself into every conversation about computer security again coming at a cost of his credibility.
Finally, you want to understand my need to pull Schneier down. I don't care if he's smart. I care that he's a guru. He's listened to uncritically by lay professionals, and his opinions about the problems they face are often not valuable. I'll add that Schneier's reputation in cryptography --- a field I am not a part of --- is not ironclad. If you want to stick up for a scientist, start with their citation record. Let us know what you find.
Don't you kind of think homomorphic encryption is a big deal for what it allows? I mean, at it's core, running arbitrary computation on encrypted data for the later consumption of the decrypter is a very big deal, and can be a Cloud game-changer.
Schneier may not be the world's greatest guru, but he knows a lot and he writes well, which makes his opinion more relevant on average than almost anyone else's. If you want a similar amount of "street cred", write a book.
No seriously, I'd read a book by you guys, just write it, please.
I start caring about crypto (and security) when it gets deployed in the real world, so I can break it. We ship a product, but for the most part, I am myself a professional abuser of software. So there you go, re: homomorphic encryption.
As regards "street cred", look, you can assign whatever credibility you want to the guy. I'm telling you, from the trenches, you are often going to be worse off for basing decisions based on what he says. Sure, you'll say, you don't base decisions off what some random pundit on the Internet says, and I say to you, "good on ya". But lots of people do, and so taking the piss out of him is a noble enterprise in my view.
Comments
"Guru" is probably the right word to use for Schneier at this point, and here's another great example of him inserting himself into a story he has no involvement in, making comments that betray a complete lack of awareness of the context of the story he's commenting on. Par, unfortunately, for the course.
It is doubtless the case that Schneier is fielding constant phone calls from trade reporters asking for his opinions on the security news of the day. Taking those calls, and writing the op-ed-style pieces that generate them, is probably the bulk of his job description. And so it's to be expected that he's going to be asked questions about things like Chrome's "virus-proofness", and having given no thought to Chrome or its architecture, be at a loss for pithy commentary. Hence, "2+2=3". Thanks, Bruce.
But before you feel too much sympathy for him, remember that he always has the ability to tell the reporter, "sorry, I don't know enough to comment intelligently on this story".
You've been interviewed by a reporter, yes? His very next sentence could have been something like, "It's not going to be virus-proof, but I'm glad to see they're thinking about security early. There is still a lot that can be done at the operating system level to improve security for the user."
The reporter would have cut that part out. It's not controversial enough. You could do the same thing with his blog post on homomorphic encryption if you took the phrases, "Gentry’s scheme is completely impractical," and "I think he’s being optimistic with even this most simple of examples," in isolation from "practicality be damned -- this is an amazing piece of work," and "I never expected to see one [a secure fully homomorphic cryptosystem]."
I don't understand this need to pull Schneier down. He's a smart guy, most of his writing is good, and he helped design a cipher that came pretty close to being selected for AES. Anyone who enters the media game is going to end up getting a bit caricatured.
You'll note that I didn't comment on his post about Gentry's homomorphic encryption scheme, for two reasons: (1) homomorphic encryption is a very boring topic, and (2) I don't feel like I have an authoritative argument for Schneier not being qualified to talk about it. Having dispensed with the straw man in your second graf, I'll take the 1st and 3rd in order.
I have been interviewed by reporters. And I have, in fact, made lots of mistakes with them. Security researchers are unnaturally attractive to trade reporters, and there's business value in cultivating contacts with them, and I've definitely let that process run too far in the past.
So, a mistake is a mistake. And thus, regarding your first graf, two responses:
(1) I stand by my original argument that Schneier doesn't appear to be close enough to Chrome OS security to comment on it, and his comments appear to misconstrue what Chrome OS is aiming for, and
(2) I stand by my original argument that this is an example of Schneier's business objective of inserting himself into every conversation about computer security again coming at a cost of his credibility.
Finally, you want to understand my need to pull Schneier down. I don't care if he's smart. I care that he's a guru. He's listened to uncritically by lay professionals, and his opinions about the problems they face are often not valuable. I'll add that Schneier's reputation in cryptography --- a field I am not a part of --- is not ironclad. If you want to stick up for a scientist, start with their citation record. Let us know what you find.
Don't you kind of think homomorphic encryption is a big deal for what it allows? I mean, at it's core, running arbitrary computation on encrypted data for the later consumption of the decrypter is a very big deal, and can be a Cloud game-changer.
Schneier may not be the world's greatest guru, but he knows a lot and he writes well, which makes his opinion more relevant on average than almost anyone else's. If you want a similar amount of "street cred", write a book.
No seriously, I'd read a book by you guys, just write it, please.
I start caring about crypto (and security) when it gets deployed in the real world, so I can break it. We ship a product, but for the most part, I am myself a professional abuser of software. So there you go, re: homomorphic encryption.
As regards "street cred", look, you can assign whatever credibility you want to the guy. I'm telling you, from the trenches, you are often going to be worse off for basing decisions based on what he says. Sure, you'll say, you don't base decisions off what some random pundit on the Internet says, and I say to you, "good on ya". But lots of people do, and so taking the piss out of him is a noble enterprise in my view.
And I am all about the nobility.