4 ms·
Encryption: getting easier every day Authentication: difficult if not practically impossible[1] [1]Outside of organizations where members follow rules. If
by gwu78 10y ago
Encryption: getting easier every day
Authentication: difficult if not practically impossible[1]
[1]Outside of organizations where members follow rules.
If you agree, then here is a question:
Why does SSL, hereafter "TLS", not separate the two concepts for the user?
The user is never presented with the information that TLS-enabled software can encrypt data, e.g., in transit, requiring almost no effort on her part, but that there is no reliable way for software alone to verify an endpoint or content on an untrusted network such as the internet.
Instead she is led to believe it is all or nothing, and that the software she is using is performing both, with equal rates of success.
Verification (authentication) requires human effort.
Software can help but computers alone cannot solve the problem.
Delegating verification to third parties, e.g., a "CA system" or a startup, is antithetical to the goal of encryption -- protection from third parties. It does not solve the problem.
- marcosdumay 10y ago> Why does SSL, hereafter "TLS", not separate the two concepts for the user? Because encryption without authentication is worthless. It's Alice passing a secret message on paper to anybody on the street that will claim to be Bob.
- gwu78 10y ago"... encryption without authentication is worthless." I have heard this before, i.e., seen it in HN comments. There are uses for encryption without authentication. I am not an expert on encryption. This is all I will say. In your example, Alice may not know where Bob is, but if the message is encrypted with Bob's public key then unless I am mistaken only Bob can decrypt it. She can leave the message somehere for Bob to get it. Does Bob need to know the message was sent by the real Alice? Do web servers check client certificates? Assuming what you say is true, that unless your authentication solution is as good as your encryption solution, then the encryption is "worthless", then I think there is a large amount of "worthless" encryption being performed using TLS. How many users have control over routing on the internet? Even if a user had a solution to verify a physical computer on the internet, e.g., SSH, whether she could actually reach that computer in order to verify it is not necessarily within her control. She might as well just assume a third party, i.e.. "anybody on the street", could easily obtain a copy of the encrypted data she is transferring. File encryption can be useful without any authentication of any other party. Some files are not "messages" intended for any other party to see.