Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Is this meant to be a general statement or just a response to some comment?

One thing I do not like about the popular "strong" encryption solutions are that they are tied to relatively "weak" authentication solutions. Instead of two programs that each do one thing, we are instructed to use one program that does two things.

I prefer that encryption and authentication were are viewed as distinct programs. If desired they can be used together. Sometimes we may not wish to rely on the hope of an "encrypted channel", but instead we might just want to send an encrypted blob over an untrusted channel (=the internet).

Obviously it makes sense to send your encrypted blob to the correct destination, but that does not mean you _must_ use encryption to verify the destination is the correct one; it is an option, but not the only one.

For example, it is possible to do the authentication part via some old-fashioned method that does not require the internet.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: