4 ms·
Realistically speaking, if your scenario is that the US government might capture and torture you for encryption keys, then your number 1 priority should be phys
by JohnStrangeII 6y ago
Realistically speaking, if your scenario is that the US government might capture and torture you for encryption keys, then your number 1 priority should be physical security of your communication devices and the people who operate them. Your number 2 priority should be preventing other side channel attacks, e.g. the operating systems you're running on your endpoints and things like the Management Engine on Intel chips and the equivalent on AMD chips, as well as other possible backdoors in the hardware and your supply chain. Remember, the NSA intercepts mail-order hardware and modifies it and the CIA runs hardware companies.
Once you have taken care of these priorities, you can start worrying about the soundness of your encryption. Inventing safe encryption if you're not overly concerned about performance is really not hard, even experienced laymen can do that by using existing cryptographic primitives. You can even make it quantum safe. (It should be, in the described scenario.) If you think that is not within your capabilities, then you're probably right, but then you've already failed at task 1 and 2 anyway.
For the remaining 99.9999% of the population this is not a realistic threat scenario, and it's best to use a well-established cryptographic library with the recommended defaults.
- 6AA4FD 6y agoThis kind of thinking is what inspired by (root) parent comment. If we don't like our government putting people in the "capture and torture" risk management scenario, we need to act politically to prevent that from happening, because there is very little we can do technically to prevent such a thing.