Hacker News new | past | comments | ask | show | jobs | submit login

you can trust their skills and ability, but trusting their intentions shouldn't necessarily follow.



If I trust someones cryptographic abilities but don't trust their intentions, then I should still use their cryptosystems over my own.

If I use e.g. Bernstein's cryptosystem and he's evil, then he and whoever hires him can read my data.

If I use my own or your cryptosystem, then either the cryptosystem or implementation definitely (with a much, much greater confidence than any trust issues) is horribly broken due to some bug, oversight or side channel, and I just haven't noticed yet. So the end result is that everyone can read my data - sticking with someone evil would have been more secure than rolling my own.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: