Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So it's based on my experience. I'm an Engineer in secure comms. I absolutely see the "family of mathematics" card as a sign of incompetence. In the space, nobody talks about the mathematics. The people implementing algos might, but they're in a different space.

A savvy customer wants to know which algos you're using, and how you're using them, where you're using them. EC? RSA? Other? Which implementation are you using, is it audited? Standard based? Working with government, is it FIPS or similar? What does your KEx and KDF look like? Data at rest security? WHAT are you storing, and sending? Transport security? Metadata? Development practices?

There are a LOT of things a customer wants to know, and which or how many "family(/ies) of mathematics" has never been one of them, in my experience.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: