4 ms·
Again, the article states very clearly and explicitly that WindsorGreen should not impact people using strong crypto. You criticize a reference to RSA-4096 as
by mapgrep 9y ago
Again, the article states very clearly and explicitly that WindsorGreen should not impact people using strong crypto.
You criticize a reference to RSA-4096 as implying RSA-2048 is weak. That reference was made in a quote by bunnie huang, a security researcher, who, like us, was using it to illustrate a broader point, with no insinuation that 2048 is weak. The quote was surrounded by higher level paragraphs from us saying, again, that contemporary crypto should be safe from WindsorGreen.
If we were advancing that narrative — that crypto is useless or will soon be rendered useless — I can see why you'd be concerned. But you have to blow past explicit, lengthy blocks of text saying the opposite of that, and ignore them, to come to that conclusion.
(I'm also not sure why we'd promote that narrative when we ourselves put a lot of effort into crypto education, here's just from Micah Lee and the video team that works with him, only a portion of what I'm talking about: https://theintercept.com/staff/micah-lee/ https://theintercept.com/staff/micah-lee/ )
- tptacek 9y agoI like Bunnie Huang as much as anyone here. Your publication chose to quote him in a manner suggesting that people should be adopting RSA-4096 because of NSA supercomputers. I think it's fair to criticize you for doing that. I'm not sure why I'm meant to care about the work you've done to educate people about cryptography, or how that's germane to the discussion. I assume The Intercept is broadly supportive of cryptography. That doesn't mean you can't write a bad story about it, or even that your incentives will tend to keep you from doing that --- those incentives, after all, are mostly about growing a readership, just like any other publication.
- refulgentis 9y agoIt's eerie to read this thread - I know little about crypto, after reading the article, I thought the NSA was clearly planning to break all HTTPS traffic. Its unimpressive to watch whoever you are (author? Publisher? Someone who repeatedly implies they have a connection to The Intercept but doesn't explicate it?) to be argumentative with, frankly, poor excuses whenever someone points out its possible for someone to misread the article exactly the way I misread it.