3 ms·
The key analogy is perfect for the private key and for symmetric keys. Publishing those is always bad and means you need to rekey immediately just like losing a
by fc417fc802 17d ago
The key analogy is perfect for the private key and for symmetric keys. Publishing those is always bad and means you need to rekey immediately just like losing a traditional physical key to a secure building would.
The public counterpart is tricky to name but I think attaching "public" to it makes the intended usage plenty clear. There isn't really a physical counterpart unless you consider maybe those machines that check for counterfeit cash but even that's not a great fit because the pubkey is simultaneously analogous to a lock box.
- tialaramex 17d agoNot quite. The analogy works for secret keys (what you're calling "symmetric keys") but a private key is unlike real world key analogies because as you'll quickly discover if you deploy real world keys in a high security environment people can examine the lock to figure out the correct key. The whole point of private keys is that this cannot work in a public key system. That step does not exist. It is true that publishing your private key is bad but you'd hope the name makes that pretty clear. Despite the way I remember (U2's "The Fly" lyrics, "A secret is something that you tell one other person, so I'm telling you, child") people generally do not understand that the whole point of secrets is that at least two parties know, which means you might always be betrayed by somebody you think is keeping your secret. For a private key it's easy, don't tell anybody, nobody knows, you can't be betrayed, done. For example Hacker News learns my password to this web site every single time I sign in because that's just a secret. We've known how to do better for decades but only a handful of systems I use (e.g. Google) do so and all of them have a "traditional" password option which is like discovering your aeroplane still has a smoking section in 2026.
- fc417fc802 16d agoI don't see the issue. Attacking a physical lock as you suggest is analogous here to breaking the cryptography in some way. So the NSA busts out its sooper sekrit quantum computer ... The inability to betray is a sharp observation but I think the analogy still holds flawlessly. It's a physical lock that you haven't handed out the key for so you're the only one with access to it. However the public counterpart still defies easy explanation. Why did you put "symmetric keys" in scare quotes? Is that not the common term in your neck of the woods when speaking about symmetric crypto?
- TeMPOraL 16d agoAgain, the "lock" part is the dumb part. Encryption scrambles the data. Key is the piece of information that lets the information be scrambled in specific way so that it can be unscrambled by someone in possession of the same (symmetric) or complementary (asymmetric) key. The only "lock" in the whole thing is the scrambler (encryption software), and that one is usually publicly known and available. Obvious way to make this clear: if "keys" were a lock, the original data in readable form would be there, accessible if you found a way to bypass or destroy the lock. The whole point of encryption as opposed to locking is that you cannot do this, because the data itself is scrambled - and thus you don't even need to ship any "lock", just the scrambled data, because the "lock" is something everyone already has or can procure.
- vel0city 16d ago> the whole point of secrets is that at least two parties know This isn't true. If I do something privately by myself and never tell anyone it's still a secret. If I have a hidden compartment in my desk to hide things and I'm the only one who knows about it, it's a "secret compartment". A secret doesn't have to involve a second party at all.
- gowld 16d agoAnd in fact, we have a dedicated term for shared secrets
- bigfishrunning 16d ago> For example Hacker News learns my password to this web site every single time I sign in because that's just a secret. I don't know the details of the login system for Hacker News, but i would expect they learn "a hash of your password and some salt" for every login, and your password isn't just transmitted to them. If they're doing things correctly, they're only storing a hash of your password, and can't work backward to get it -- that's a big If, and lots of places get it wrong.
- DaSHacka 16d agoI've never actually found a site that computes the hash client-side and sends the finished hash to the server, the vast majority just send the regular password to the backend to be hashed and compared (and HN is no exception). And if you think about it, there's really no advantage to sending the hash every time anyway. An attacker that MITMs your traffic once can just resend the static post-computed hash to the backend anyway. The only advantage would be preventing an attacker from seeing a password string you may re-use for other sites, but so long as it's unique for HN alone (surely we all use password managers on here? :-) ) it doesn't matter.
- tialaramex 16d ago> I don't know the details of the login system for Hacker News, but i would expect they learn "a hash of your password and some salt" for every login No. That would be a terrible idea and so that's not what they do. You can go see for yourself, it's an HTML form, the text field with your password in it is submitted to their web server, much in the same way this larger field full of comment text was sent. If you think a bit harder you'll realize why your approach would be a bad idea. A bad guy who has obtained the password hashes (for example by dumpster diving, or an SQL extraction) can just play back a hash they've seen without ever knowing your password, you've rendered the knowledge of the password useless. Yes, that means if you've been around long enough, sites which had passwords but did not use TLS or before that SSL, were sending your actual password, unencrypted, for any snoop to see. That might seem crazy, but because I'm an old man when I first used the Internet it was normal to send your password, letter by letter in plain text, to connect to a remote Unix machine. The "Secure Shell" you take for granted today did not exist until July 1995.
- TeMPOraL 16d agoIt's not perfect for symmetric keys at all, because the fundamental fact about locks and keys is that a lock sits on the outside of the thing you're protecting, attaching to it or to a container in which the thing is placed. Encryption is about directly scrambling the protected thing.
- yencabulator 16d agoThe mental model is that encryption is a locked box you can only open with the key.
- TeMPOraL 16d agoThat's a dumb mental model, is what I'm saying. The original sin of cryptography/cybersecurity metaphors.
- yencabulator 15d agoBetter than calling encryption "scrambling".
- fc417fc802 15d agoWhat's dumb about it? I'd suggest that it's slightly abstract and argue that there's nothing wrong with that. It fits perfectly and it's readily understandable. For example a VPN connection lends itself to being described as a pipe. That already equates the encapsulating protocol with a physical barrier regardless of the presence of cryptography. I think you're just being overly literal, something which will kill almost any decent analogy regardless of topic.
- TeMPOraL 15d agoYou have a very large subthread debating downstream confusions, which were previously debated in millions of such discussion on-line too. It's a confusion everyone has to learn to live with when first exposed to concept and the metaphor of "keys" and "locks". And it's because it does not fit. Locks and keys are distinct kinds of objects, and are external to the thing being protected, with lock itself being attached to the thing being protected. Only the key can be distributed separately and copied; you come into possession of the security mechanism and the protected object together, they're literally unseparable (that's the point - if you can separate the lock from the thing, you don't need the key anymore). Encryption in contrast is (reversibly) destroying the thing being protected, the "locking mechanism" is public and same for everyone and therefore you already have a copy, and you can't "bypass" it because the very thing being protected has been destroyed (scrambled) and you cannot undo that without having the "key". There's no 1:1 mapping of any concept from physical locks and keys to encryption. It's a fundamentally dumb analogy that people run away with, because at first look it seems to have some semantic similarities.