4 ms·
"... encryption without authentication is worthless." I have heard this before, i.e., seen it in HN comments. There are uses for encryption without authentica
by gwu78 10y ago
"... encryption without authentication is worthless."
I have heard this before, i.e., seen it in HN comments.
There are uses for encryption without authentication.
I am not an expert on encryption. This is all I will say.
In your example, Alice may not know where Bob is, but if the message is encrypted with Bob's public key then unless I am mistaken only Bob can decrypt it. She can leave the message somehere for Bob to get it.
Does Bob need to know the message was sent by the real Alice?
Do web servers check client certificates?
Assuming what you say is true, that unless your authentication solution is as good as your encryption solution, then the encryption is "worthless", then I think there is a large amount of "worthless" encryption being performed using TLS.
How many users have control over routing on the internet?
Even if a user had a solution to verify a physical computer on the internet, e.g., SSH, whether she could actually reach that computer in order to verify it is not necessarily within her control.
She might as well just assume a third party, i.e.. "anybody on the street", could easily obtain a copy of the encrypted data she is transferring.
File encryption can be useful without any authentication of any other party. Some files are not "messages" intended for any other party to see.