Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You accept that, unless you're the NSA, GRU or whatever the Chinese counterpart is called, you will have to.

Do you really have the talent in your organisation to develop a better cipher than AES or ChaCha? If not, go with something that exists. According to Snowden, even the NSA can't just break PGP if you use it properly.

Do you have better coders than OpenWhisperSystems? You're going to have to trade off relying on someone else's software versus the chance your own coders make a mistake. I'd say the latter risk is usually the bigger one - even the Sony PS developers messed up on the "don't reuse nonces" bit.

Do you have your own chip fab? If not, you're going to have to hope whatever you're using doesn't have too many backdoors.



There is huge difference between relying on libraries or independent implementations of software in a form of source code that may or may not have bugs, and relying on an organization that sends binary blobs to you, that has to keep their development process secure, infrastructure secure, physical security, developers not compromised, backdoors not forced through laws, state agencies not threatening and forcing to implement backdoors, etc. OpenWhisperSystems essentially asks you to trust they can do all of that, but of course they can't, while an open source PGP implementation doesn't ask you to trust them and rely on their competence on running highly secure infrastructure. So, don't be fooled by propaganda organizations put out, there is a huge difference in what you can rely on and Signal here is exactly as weak as EncroChat.


Yeah, agreed. So you just have to pick carefully who you rely on.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: