4 ms·
Your assessment of Colin's article is unfair. He does do better than 'picking on them for saying "military-grade cryptography."' In particular, he points out Zu
by briansmith 17y ago
Your assessment of Colin's article is unfair. He does do better than 'picking on them for saying "military-grade cryptography."' In particular, he points out ZumoDrive's encryption is not protected by a key known only to the owner of the data, and he points out that there are plenty of points where the plaintext and/or keys can leak out for a variety of legal and technical reasons.
Colin does describe some technical aspects of TarSnap: at http://www.tarsnap.com/security.html http://www.tarsnap.com/security.html and http://www.tarsnap.com/crypto.html http://www.tarsnap.com/crypto.html. In addition, he's written some very good articles about practical issues regarding crypto on his blog. (If I was going to criticize him for anything about his blog, it would be the poor UI for navigating the archives.)
Also, is this really a case of one company simply "bashing" a competitor? I don't think so. From reading his blog, Colin seems to be very passionate about crypto and security. This blog post is the same kind of reaction that many of us who are passionate about security and privacy would have. See Schneier's numerous "doghouse" posts for example. Also, see Colin's blog post where he explained what was wrong with AWS signing V1; AWS was a partner, not a competitor.
Colin's criticism of SSL/TLS should be expanded upon so we can see exactly why he thinks it is only good for key management. However, he is correct that "client encrypts, client sends to server, server decrypts, then server encrypt again with its own key" is not a great design.
Also, Colin doesn't mention anything about OpenSSL in his post.
(Non-)disclaimer: I've never met Colin or anybody involved in this discussion, and I have no business dealings with anybody involved.