5 ms·
Cryptography is not dead. Just because some motivated governments can theoretically attack your machine does not mean that cryptography is not useful, because
by codex 13y ago
Cryptography is not dead. Just because some motivated governments can theoretically attack your machine does not mean that cryptography is not useful, because for 99.9999999% of us, that outcome will never happen--and if it does happen, the information will not leak to those you want to keep it from (unless that's the government, of course). Cryptography still keeps us safe from all but three or four entities.
Put another way--the FBI can sneak into my apartment any time they want by picking my lock, but I still lock my door.
- brazzy 13y agoThe article argues that your assumption that "advanced" techniques used by motivated governments now will stay the exclusive domain of those governments is wrong. IT systems and networks have become so large and complex that vulnerabilities are everywhere. Your home computer may have a small enough attack surface by itself, but is constantly communicating with systems who don't - and much of your important data is kept in those anyway.
- pyre 13y agoSome of those attacks are resource-intensive though. Only governments have the financing to carry them off, at least at the current time, and into the near-future.
- ds9 13y agoCryptography is alive and well, but not because we can redefine the goals to disregard the most powerful adversaries. It's alive and well because there are ciphers that remain essentially unbreakable and are likely to remain so in the forseeable future. The title is somewhere between misleading and dishonest. It's like saying that door locks are "dead" because burglars can go in the windows - in reality there's nothing wrong with the door locks, and the correct response is not to abandon the door locks but instead to secure the windows too (no pun intended). The fact that there are side attacks is not a flaw of cryptography, rather it is a part of the environment in which it is practiced, and besides the attackers' workarounds are in principle subject to being defeated or avoided.
- chris_mahan 13y agoOne does not need to break the cyphers if one can obtain the decryption key, either by locating them, or "enhanced interrogation techniques" them out of biological systems.
- mpyne 13y agoNeither of which enable mass surveillance though, which is the major threat from what I can tell. Rubber-hose cryptanalysis has been possible since the Caesar cipher.
- chris_mahan 13y agoIf there were hundreds of millions of sites to compromise, I agree. But if one obtains, and keeps obtaining, Google, Facebook, Microsoft, and Yahoo private certificates, then one can access the private information of billions of people.
- Florin_Andrei 13y ago> for 99.9999999% of us, that outcome will never happen It may actually happen for quite a bit of people. I think your percentage is about people where it makes a difference in their life whether or not the Three Letter Agencies decrypt their traffic or not.
- FBT 13y ago> for 99.9999999% of us, that outcome will never happen Note: As a fraction, the number you give for this is that it will happen to one in a billion people. You are claiming that there are 8 people in the world that this outcome will happen to. While your general point may be true, I want to emphasise that this number is quite absurdly off. (It's off by at least two or three orders of magnitude.)