8 ms·
This is the exact attitude that has gotten us where we are today (as in, pervasive bad security). "Do what you've always done, you'll get what you always got."
by packet_nerd 8y ago
This is the exact attitude that has gotten us where we are today (as in, pervasive bad security). "Do what you've always done, you'll get what you always got."
- x220 8y agoI disagree. It is possible to make decent, good, and perhaps great security that is easy to teach and not too inconvenient that users will rebel. I think it is unreasonable to keep someone from using GnuPG in a legal fashion because average people cannot use it. You will never find signing software with sufficiently bulletproof security that average people can use. To suggest such also implies that average people need to regularly perform notarial acts, which I think is imaginative.
- packet_nerd 8y agoThe guy in the cubical next to me made a comment along the lines of "security is always inconvenient and hard" earlier today. And he's just expressing a widespread attitude, but I think it's not (or at least doesn't need to be) always true. If we do it right, we can make simple systems built from the ground up on fundamentally secure principals. Example: Think of the simplicity and security of a cryptocurrency transaction as compared to a traditional bank. The crypto transaction is so much simpler, easier, and much much more secure. I work in a bank, and there are so so many moving parts all with a myriad security weaknesses all chained together to make a transaction happen. First there's the web portal where the customer initiates the transaction. This is HTTPS which has well known flaws and so many things that could go wrong. Then his transaction goes into a SQL DB in the bank intranet, could be attacked hundreds of ways, then scripts process it into an ACH file, encrypt it with PGP, and SFTP it to the Fed. Those PGP keys were exchanged through unencrypted email, and the SFTP password was exchanged over the phone. Then the Fed uses a similar process to send it on to the destination bank, each step adding additional weak points. The cryptocurrency transaction, on the other hand, is a well defined mathematical problem with no ambiguity, few variables, and a few easy concepts to understand. Yes, there are a handful of things that could go wrong, but they are well define and well understood. In comparison to the bank transaction, the whole thing is just so simple, beautiful, and easy.
- fwip 8y agoI would argue that the failure modes of a bank transfer are much better understood than any cryptocurrency. Or was the parity wallet multi-sig attack something that most lay-people knew about as a risk before it happened?
- gruez 8y ago>Or was the parity wallet multi-sig attack something that most lay-people knew about as a risk before it happened? IMO that's more of a problem with smart contracts than with cryptocurrencies as a whole. if you allow anyone to write code that controls millions of dollars, there's going to be ten different implementations and a hack in one of them is virtually guaranteed. on the other hand if the multisig mechanism is part of the network protocol, there's only 1 implementation which will be better scrutinized. even if there was a bug, at least the intention is clearly conveyed and can be fixed with a non-controversial hard fork. see: bitcoin's block reward integer underflow hack vs ethereum's DAO hack.
- packet_nerd 8y agoI'm responsible for managing 30+ firewalls at my bank. If any one of them is incorrectly configured an attacker could get into our network and all that would take is a tiny incorrect detail on one line. And I'm keenly aware that I'm a mortal human being and very possibly could make such a mistake. Or the network could be compromised through any of hundreds of other ways: email, USB stick, insider attack, etc. etc. etc... And that's just my bank. Any given transaction will go through several all with similar weak points, and some of them with firewall admins even less competent than myself. To me there's just no comparison. The scale of failure modes or attack points for a bank is way way bigger than any cryptocurrency. The reason it works at all is banks have well-paid guys like myself pouring over every detail and keeping things working.
- badrabbit 8y agoYou can use it,but your citize peers,lawyers ,judges and anyone opposing you in court need to also be able to use it.