Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Being cryptic is bad -- in "secure code" and just about everywhere else. Unfortunately, that's not the point the commenter made at all.

As to your praise of the notion that the author of an open, civilian protocol is making his protocol less secure by revealing what hash functions he's using, well, I'm just going to say that I'm a practitioner too and I've never heard of openness about the algorithms involved as a sign of bad security. Indeed, I've never heard Schneier once make that point, much less hear him make it often and I read Cryptogram almost every month. Sorry, but I'm calling bull on that one.

The only folks who get a pass on not revealing their algorithms are NSA cryptographers who create Type 1 National Security systems and that's only because they have a large, knowledgeable community of cryptographers within the organization that does their peer review, thus obviating the need for vetting their protocols with the greater academic community.



You just spent 3 grafs kicking a straw man, which you'd know if you'd read the article. This is a discussion about an article. The source code for the software the article is about was published in 2005. Nobody argued that he should have kept his algorithms secret; they argued that bragging about them in an article didn't make him look more competant.

Also, you already said you weren't a practitioner; which is it? Your use of the term "Type 1 National Security systems" allows me an educated guess, but you could clear it up.


Let's see, I replied to someone's comment with a valid criticism. I just read the entirety of Zed's piece and, lo and behold, my argument against the comment still stands. (Whether or not Zed's protocol still stands is an open question.) Meanwhile, you've been attacking a strawman the whole time.

Now you're trying to personally attack me. I'm not sure what your problem is or what you're trying to prove, but I am a practitioner.

See here:

http://csrc.nist.gov/publications/nistpubs/800-85B/SP800-85b... [PDF]

or here:

http://csrc.nist.gov/publications/nistpubs/800-83/SP800-83.p... [PDF]

or here:

http://csrc.nist.gov/publications/fips/fips201-1/FIPS-201-1-... [PDF]

(You won't find my name in that last document, as authors and supporting researchers are not listed on FIPS.)

I'm not going to ask about your credentials because, frankly, they don't interest me. You've jumped the shark and I'm done responding after this. Don't make this thing personal; you've got a problem with my comment, do us all a favor and keep it there. You trying to start a pissing match with me is boring for everyone and ultimately wastes both of our time. Chill.


You're right. I'm infinitely more irritated at the mentality conveyed by Shaw's document, that "security" is a combination of using the most "advanced" crypto constructions and using parsing tools to avoid superficial overflows than I am at you for arguing with people about a post you didn't bother to read.

For that, I apologize.


All good, man.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: