While applauding the stated mission of Open Whisper Systems to make cryptography usable by large numbers of people I think it is fair to hold Moxie & Co. to the same high standards to which they held PGP: https://moxie.org/blog/gpg-and-me/ The journalists who depend on it struggle with it and often mess up (“I send you the private key to communicate privately, right?”), the activists who use it do so relatively spari…
2017 Levchin Prize for Real World Cryptography
21–30 of 35 posts
Re: 2017 Levchin Prize for Real World Cryptography
#22Earlier quoted context omitted.
Moxie was contrasting the different perspectives that communist and fascist leaders had about what caused their success, for the purpose of an analogy. He was not contrasting communism with fascism. Please learn to distinguish the two.
I'm very clear in my comment: a. "The idea that communist leaders felt any different...". In other words "the different perspectives" they had about what caused their success. I do not believe they had different perspectives, except externally. b. I think it's pretty clear that Moxie favours what he perceives as the superior point of view of one group over the other and he reinforces that by himself clapping with the…
A ideological fascist utopia looks very different than a communist one.
One may rightly gripe that in practice there is no difference, or that those in the respective governments did not believe in the ideas they espoused and instead worked towards different ends.
But I can't believe that 100% of those following the ideologies ignored their tenets.
Re: 2017 Levchin Prize for Real World Cryptography
#23While applauding the stated mission of Open Whisper Systems to make cryptography usable by large numbers of people I think it is fair to hold Moxie & Co. to the same high standards to which they held PGP: https://moxie.org/blog/gpg-and-me/ The journalists who depend on it struggle with it and often mess up (“I send you the private key to communicate privately, right?”), the activists who use it do so relatively spari…
Can you find a single practicing cryptographic engineer who will go on the record as saying that PGP (in any of its incarnations) and email is better than Signal Protocol for message encryption?
v1 of the internet as used now seems wildly naive of state surveillance.
v2 may be better, but if most traffic goes encrypted, then there are going to be a lot more attacks (both legal and extra-legal) against the nuances of implementations.
v2 is certainly an improvement on v1. But one of the reasons v1 was deployed is because we believed things like "The US government would never tap traffic at the backbone" or "The US government would never tap private links between data centers."
Valuing both, I think it's important to keep eyes on the future so in 10 years we don't look back on statements like "The US government would never compell Google / Microsoft / Facebook / Whisper to distribute a poisoned version of their application" with the same amount of surprise.
Re: 2017 Levchin Prize for Real World Cryptography
#24While applauding the stated mission of Open Whisper Systems to make cryptography usable by large numbers of people I think it is fair to hold Moxie & Co. to the same high standards to which they held PGP: https://moxie.org/blog/gpg-and-me/ The journalists who depend on it struggle with it and often mess up (“I send you the private key to communicate privately, right?”), the activists who use it do so relatively spari…
Can you find a single practicing cryptographic engineer who will go on the record as saying that PGP (in any of its incarnations) and email is better than Signal Protocol for message encryption?
Re: 2017 Levchin Prize for Real World Cryptography
#25Earlier quoted context omitted.
Can you find a single practicing cryptographic engineer who will go on the record as saying that PGP (in any of its incarnations) and email is better than Signal Protocol for message encryption?
Can you give the 5 cent description of why Signal would be preferred to encrypted email?
PGP and email is essentially the opposite.
Re: 2017 Levchin Prize for Real World Cryptography
#26Earlier quoted context omitted.
Can you find a single practicing cryptographic engineer who will go on the record as saying that PGP (in any of its incarnations) and email is better than Signal Protocol for message encryption?
If one is going to be paranoid, then one should at least be consistently paranoid. v1 of the internet as used now seems wildly naive of state surveillance. v2 may be better, but if most traffic goes encrypted, then there are going to be a lot more attacks (both legal and extra-legal) against the nuances of implementations. v2 is certainly an improvement on v1. But one of the reasons v1 was deployed is because we beli…
Re: 2017 Levchin Prize for Real World Cryptography
#27Earlier quoted context omitted.
If one is going to be paranoid, then one should at least be consistently paranoid. v1 of the internet as used now seems wildly naive of state surveillance. v2 may be better, but if most traffic goes encrypted, then there are going to be a lot more attacks (both legal and extra-legal) against the nuances of implementations. v2 is certainly an improvement on v1. But one of the reasons v1 was deployed is because we beli…
I don't understand what this has to do with whether we should use risky, leaky cryptosystems like PGP over things like Signal that were designed specifically to deal with these threats.
Signal is better than PGP.
Running crypto without PFS in this threat environment is an irresponsible bet to make with data.
My point was that failing to continue to maintain vigilance, even if it sounds paranoid, is also irresponsible. Unless one is willing to be that we have a perfect crypto system, some amount of humility (as evidenced by Moxie's speech) is warranted. Else we'll be talking about Signal in 20 years in the same way we're talking about PGP.
Re: 2017 Levchin Prize for Real World Cryptography
#28Not OP, but I sense perhaps a limitation of HN; articles with comments where the comment is the submission get conflated with submissions about the article itself. (EDIT: the submission's URL has now been changed from a particular reddit comment at https://www.reddit.com/r/crypto/comments/5m0zpo/moxie_marlin... to a different announcement about the prize. The rest of my post as it originally stood follows.) Reproduci…
I first heard that applause story from Žižek (but it might not have originated with him?) https://www.youtube.com/watch?v=zvgl0Oy5wx8#t=13m33s