6 ms·
> To me, it's probably good enough. Your bar should be a little higher. > I mean any sophisticated adversary will use the traditional methods of bribery and c
by CiPHPerCoder 4y ago
> To me, it's probably good enough.
Your bar should be a little higher.
> I mean any sophisticated adversary will use the traditional methods of bribery and coercion with violence to obtain intelligence and influence the course of events.
Okay, but we're not talking about someone who failed to meet an ultra paranoid threat model. We're discussing an encryption technique that can be bypassed by anyone who bothered to do the first 2 sets of the cryptopals challenges.
> Yes it doesn't handle an edge case in the same way body armor doesn't handle a 20mm depleted uranium chain gun, but it probably handles the likely threats well enough.
The edge case is "someone with any knowledge about applied cryptography decided to kick the tires, even if only for the laughs". The code is that bad.
- brudgers 4y agoDo you think it is better than nothing? Because nothing is what the alternative was. It wasn’t Moxie Marlinspike on retainer. The city council chose from the alternatives to an RFP and probably made the choice in part based on who showed up and pitched at the Tuesday night meeting where the purchase was on the agenda. And those people probably met with staff beforehand on a sales call. Whatever better alternative you are imagining would have had to have done those things. Things which are expensive and more important than code quality. I could set my bar higher, but for living in the real world and that a higher bar would conflict with the high bar of assuming people are of good will and doing the best they can. YMMV.
- CiPHPerCoder 4y ago> Do you think it is better than nothing? No. This is security theater, and it stands as an obstacle to security. They were better off with plaintext. > I could set my bar higher, but for living in the real world and that a higher bar would conflict with the high bar of assuming people are of good will and doing the best they can. Or you could just point PHP developers to my open source libraries, which have a cost of $0.00 to use and are actually secure?
- lazide 4y agoIt is probably not better than nothing, because it gives the illusion of security, while patently failing at providing it when challenged by pretty much anyone who might be interested in an attack. While charging full price. If they’d built it for an RFP asking for a honeypot, the situation would be different. So think of it as a tough looking cover over a deep pit that a contractor made for a mining company. The mining company paid full price for it to keep people from falling in. But it turns out when someone stands on it, it collapsed and dumps them into a pit because it was built wrong. Oops. Everyone would have been better off with nothing, because at least you’d know to be careful around the giant hole if it didn’t have the cover.
- deleted 4y ago[deleted]
- brudgers 4y agoSecurity theater has two acts. The protagonist makes something poorly in act one. Act two concludes with a loud Greek chorus…yet the whole thing is inconclusive as the problem is never solved. Maybe because between faang salaries, the plush lives in the academy and the patriotic satisfaction of state organs the field is left to the world’s mccaffees…and I don’t mean the McDonald’s coffee. I mean despite the lock picking lawyer, padlocks mostly work.
- macintux 4y agoSomething that is known to be insecure is often better than something that is believed incorrectly to be secure, because people can (not always, but sometimes) treat it appropriately.
- josephg 4y agoUnlike others, I think terrible crypto is often better than plaintext. But they would have gotten an actually secure system implemented more cheaply with less code by just copying some example code from libsodium[1]. The author(s) went to a whole lot of unnecessary effort and the result is an insecure, embarrassing mess. I would respect the argument of "oh, they're just picking a different point along the Pareto frontier between secure / high effort and insecure / low effort". But this is both insecure and high effort. People are piling on because it has the trademark smell of bad judgement. Its also a great learning opportunity. Its interesting hearing about all the security problems people who are knowledgeable in the field can spot! I noticed barely any of these problems! [1] Quick Reference, from the bottom of the article: https://paragonie.com/blog/2017/06/libsodium-quick-reference-quick-comparison-similar-functions-and-which-one-use https://paragonie.com/blog/2017/06/libsodium-quick-reference...