3 ms·
I didn’t mention anything about signing? I said encryption. You can do encryption all kinds of ways. In this case, I am talking about encrypting your own dat
by survirtual 4y ago
I didn’t mention anything about signing?
I said encryption. You can do encryption all kinds of ways. In this case, I am talking about encrypting your own data on a client and not allowing a server to see it. This would just require a secret key derived from a password ran through a password hashing algo.
You only need asynchronous crypto when you involve another party, so it would play a role in a trustless architecture, but I am unsure what your point is.
When I say “verify trust” of a system, I am referring to a product making a claim, such as “your data is private and we don’t sell it” — then backing up the claim by building the product in such a way such that it is impossible to sell it. Encryption + open source is just about all the way to proving that claim, and it can be verified that way.
- lisper 4y ago> I said encryption. No, you didn't. You said "modern encryption" which is generally understood to mean public-key encryption. But even so, your claim is still false because you can't trust your encryption software even if it is open source unless you build (and audit!) your entire tool chain yourself (and nowadays you have to roll your own silicon too if you really want to be sure).