4 ms·
Oh, another thing. Just to be clear, the 15 password maximum is just an implementation choice to make our life easier, but we actually think it is a liability,
by tomgag 2y ago
Oh, another thing. Just to be clear, the 15 password maximum is just an implementation choice to make our life easier, but we actually think it is a liability, and we are working to remove this limit completely. We do not think that anyone sane in their mind will ever need 15 levels of secrecy with Shufflecake, but that's not the point. The point is that, with a hardcoded maximum limit (regardless of the limit, even if it's 200 or 2000) there is a workaround that allows the user to do something very dangerous. By removing this limit (up to what is allowed by the disk size), we remove the possibility for the user to shoot in their foot. See the section "Safeword" in our research paper.