Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There will probably be a move towards signing everything digitally, so that you can know that the sender is authentic.


That works until you need to recover from key compromise. As Bitcoin has shown us, "not your keys, not your life" is not a socially acceptable security model.


“Sorry, my old phone broke, I had to do a clean install. Don’t mind the warning.”


Hopefully people will eventually see that the same way as they see a salesman saying "sorry, I forgot my uniform and business cards, but I really do represent XYZ insurance company, give me your money."


It is my experience from providing cryptographic devices to end customers (paying ones!), that people tend to lose, destroy, wipe, brick etc. their devices quite a lot.

Loss and replacement of cryptographic tokens is an everyday occurence, and it is PITA to resolve.


Caveman also say that when give shiny item to other caveman it always break because too fragile. Shiny item worthless. :'(


Public key infrastructure in general is hell to support, especially given how long lived humans are.

Imagine trying to ascertain in 2100 if a particular will signed by a 20-y.o. using a 2022 digital signature is valid or forged.

We don't even know what is going to happen to the reliability of the algorithms themselves, much less cert issuers, revocation lists etc. Companies come and go. Certain files from the 1990s are already unreadable.


Right, but that'll still leave some vectors open. Like how do I know my co-workers didn't just send all their deepfakebots to this meeting instead of actually attending? How do I know it's my children facetiming me in the nursing home and not just sending their bots to entertain me? There are some very morbid possibilities even if you require strong auth/signing/identity.


I don't agree. How is this not equivalent to the general authentication problem?

If you consider your impression from the video stream to be the "password" then there must be a second factor to confirm it. Signed audio/video streams is probably where we're headed. Devices used for real time communication will just require a TPM (many already have them).

> How do I know it's my children facetiming me in the nursing home and not just sending their bots to entertain me?

That means that in order to call you their device will have to prove it's the actual stream from the actual camera module on their uniquely identified phone. Every component of a computer system will have cryptographic elements soon enough. There's no way around this if AI ever gets to that level.


I have an idea to implement a badge that encodes the audio into a super low bandwidth stream with signing, then displays that stream as part of the video. It would tie a video stream to an audio stream to a signature. If the video is faked, the audio won't match, if the audio is faked, the signature won't match. The idea is anyone can attach the badge and be sure people know it's not deep faked.


You’re probably right. That pretty much also means the end of general unregulated computer use. Will we allow it? It’s going to be a sad day.


The parties (coworkers, kids) you mentioned in the post are not meant to be your adversaries.

If you’re in a position where you don’t trust them to not dupe you on a human level, you already lose. No technology in the world can help you


> signing everything digitally, so that you can know that the sender is authentic

This is the worst solution. We’re going towards more personal verification. If I’ve met you and dealt with you, I’ll accept your digital signature. Otherwise, I need someone (or a brand) in between to vouch.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: