As another passive observer, I am grateful for all of the time that security researchers spend on proving that many cryptographic implementations found in the wild are flawed. If they did not do this, all implementations would be closed source ROT13 with a $50k pricetag.
I'm still waiting for simple, usable crypto - but I'm not willing to settle for evidence-free, warm assurances of safety from borderline incompetents in the field while I wait for it.
I can't help but think if security researchers spent as much time on creating usable, secure software as they did in proving that other's implementations were flawed we'd be in a much better place.
Can this comment be part of the HN crypto thread drinking game? It's in every thread x10. I can't help but think if commenters spent as much time learning how to use good crypto as complaining about the time researchers spend picking apart bad crypto, all of their issues with the current implementations would disappear.
I can't help but think if commenters spent as much time learning how to use good crypto as complaining about the time researchers spend picking apart bad crypto, all of their issues with the current implementations would disappear.
Not really, because each commenter here interacts with 10's if not 100's of people who have little to no chance of learning to use good crypto.
Comments
As another passive observer, I am grateful for all of the time that security researchers spend on proving that many cryptographic implementations found in the wild are flawed. If they did not do this, all implementations would be closed source ROT13 with a $50k pricetag.
I'm still waiting for simple, usable crypto - but I'm not willing to settle for evidence-free, warm assurances of safety from borderline incompetents in the field while I wait for it.
Can this comment be part of the HN crypto thread drinking game? It's in every thread x10. I can't help but think if commenters spent as much time learning how to use good crypto as complaining about the time researchers spend picking apart bad crypto, all of their issues with the current implementations would disappear.
Not really, because each commenter here interacts with 10's if not 100's of people who have little to no chance of learning to use good crypto.