3 ms·
This is a great example of security nihilism. "This tool can't protect against every possible attack from every possible adversary, therefore it is useless." B
by secalex 10y ago
This is a great example of security nihilism. "This tool can't protect against every possible attack from every possible adversary, therefore it is useless."
Building safe, secure products at scale for real populations is a process of balancing multiple equities and addressing the most pressing and realistic threat scenarios. This always means building security protections that have theoretical failure modes. The real art is in trying to make those failures as graceful as possible while educating your huge, diverse set of users on the security properties of the product and in what situations they can rely upon it.
Doing this well is still something the entire industry needs to work on, but giving it a shot and building practical protections for real people is always a better option than throwing up your hands and giving up.
- aavotins 10y agoI agree. Every encryption can be cracked given either infinite resources or time. The goal of encryption is to make it (much) harder to eavesdrop on communications, often to a point that it's not feasible to do so anymore. Even if SS7 can be exploited in such a way that actually breaks encryption, it adds layers and layers of complexity that makes large scale spying hard or nearly impossible. These kind of attacks require individual approach, which is harder than, for example, logging all plaintext traffic.