4 ms·
Whatever it is we do, I predict that trust of internet communications will go down significantly. Maybe we will pivot back to in-person meetings for important
by TheBozzCL 2y ago
Whatever it is we do, I predict that trust of internet communications will go down significantly.
Maybe we will pivot back to in-person meetings for important transactions.
- rwmj 2y agoYou learned nothing from Crowdstrike? Some large company will claim to invent a product that solves the problem. It will fail some of the time, but that doesn't matter as customers of the product will have someone to blame. No one will ever be actually held accountable for failures as some combination of lawsuits and "you're holding it wrong" will be sufficient to deflect liability from the large company. And anyway there's no real choice as all the other large companies who also have solutions in this area are equally as bad.
- HPsquared 2y agoAnd that company will have a huge library of deepfake models stored on a poorly-secured server, which will leak.
- kreetx 2y agoHow we already authenticate is cryptography, we just need to use it more.
- moooo99 2y agoThe problem is that crypto is hard. When something is hard, people tend to pay someone else to do it. It only takes that one party to commit a private key to a public GitHub for the whole house of cards to come crashing down.
- intended 2y agoAh. There’s the sentence I was looking for! There’s many hopes riding on decentralized options. But verification is hard. Which is why all information networks tend to concentrate in some form or the other - to reduce the effort needed to authenticate
- Muromec 2y agoHTTPS is not hard, it's not even expensive anymore. Nothing stops us from using the same X509 rails backed by the same government that issued your id or driving license (or corporate access card) to do the client certs too. We even have hardware keys that are capable of that in most big corp techworkers pockets already.
- chii 2y agothe problem is that these are all trusted side channels (or regular channels that have been vetted). When an "emergency" happens, and the caller claims they're not able to use the regular channels of communication, how do you authenticate them?
- kreetx 2y agoWhen I say cryptography, I mean some means of end-to-end encryption (i.e, something which can't be faked or MITMed). What is hard is getting this implemented in consumer apps in a way that user doesn't need to know nor fully understand it, but only understand it to a degree to differenciate unsafe channels from safe.