3 ms·
It looks like this is the next step in the British tech community's long road of denial to hell: smug overconfidence tightly coupled with plain ignorance. The
by infinity0 11y ago
It looks like this is the next step in the British tech community's long road of denial to hell: smug overconfidence tightly coupled with plain ignorance.
The blog post makes an absolute fundamental mistake about security in cryptography, and even when corrected you trivialise the correction! Let me make it absolutely clear: the blog post author has no idea what he is talking about and his words disqualify themselves.
"Is RC4 secure? For this use-case, yes."
This is absolutely not an even faintly correct statement to make. NO IT IS NOT SECURE. When a cipher is developed, there is some belief on the cost of attacking it. As time goes on we gain more knowledge about it, and the believed cost for RC4 today is pretty much trivial. "Cost" refers to the cost of an attack, not the cost of research. What, you think that because the research (that has already been done) was hard, that attacks are hard? Classic naive "[in]security argument" fallacy. Also, what the fuck does it even mean to say "For this use-case" on a public blog???
There are actual formal precise definitions of "security" in crypto. Learn them. If you don't know them, you can't possibly hope to draw the correct conclusions about what cryptography actually is, and what one does with it, and you should not make wildly inaccurate public blog posts that only serve to further confirm the ignorants' own beliefs.
Yes, it is possible to make lives so hard for non-ignorant real cryptographers doing actual research, such that the economy effectively has no strong cryptography. Then you don't need to ban it outright. So dismissing this attempt by the UK government is extremely naive and dangerous.
But hey, this might backfire as good cryptographers leave the UK and head elsewhere, and the UK economy ends up with people that don't know shit about what security means.