3 ms·
what kind of "experts"? like NIST experts or experts at Microsoft? this a non-sensical meme in cryptography. it all comes down to the value at risk. at some pri
by bachback 11y ago
what kind of "experts"? like NIST experts or experts at Microsoft? this a non-sensical meme in cryptography. it all comes down to the value at risk. at some price point you can hire people i.e. invest the resources to get it right. the reality is that many security libraries and principles are ancient and infrequently updated, that much of the research in the field is academic and useless. I think its much better to think in terms of risks. good security usually doesn't more value than bad security, until there is a breach.
- angry_octet 11y agoYeah, you got it, the people at NIST and M$ are going to do better than you. 'Academic and useless' research huh? Go read DJB's website some day, it is far from inapplicable. All the research that publicly disclosed HUGE holes in SSL? I think it's incredibly important. As to good security being of little value, maybe ask Sony and Adobe (and even NSA) if they wished they had better security.