7 ms·
The post to which you were replying was amusing at the cost of a lack of rigor. Bruce generally does not sign/encrypt his email because he views email as a low
by reeses 13y ago
The post to which you were replying was amusing at the cost of a lack of rigor.
Bruce generally does not sign/encrypt his email because he views email as a low-security communications mechanism anyway.[1]
He generally advises a rational risk assessment when determining how much security to apply to a process. He often uses the example of locking doors on your house, etc.
In re PGP, he's been critical of a number of shortcomings in PGP and GnuPG since the beginning, but by the same token, one of his first hires at Counterpane was Jon Callas.
[1] http://www.esecurityplanet.com/trends/security-tips-from-bruce-schneier.html http://www.esecurityplanet.com/trends/security-tips-from-bru...