Live data from Hacker News

Can I Be Trusted?

schneier.com

41–50 of 62 posts

Re: Can I Be Trusted?

#41
On a "what do I do?" practical level, its not about trusting him.

The point is his suggestions or advice point people in a direction that they or people they trust can verify. If he were spreading false information, by now, he'd be shown to be unreliable. But for many, many years, he has consistently been not proven intentionally false. I word it carefully because he has been wrong, but being wrong is not being false.

Re: Can I Be Trusted?

#42
post #9
post #6

Earlier quoted context omitted.

Yes, he just have disclosed the reason not to be trusted. He conflates absence of evidence with evidence of absence.

> He conflates absence of evidence with evidence of absence. Absence of evidence is evidence of absence. The false statement of that form is "absence of proof is proof of absence". If absence of evidence wasn't evidence of absence, then, at best, the presence of the event and the presence of evidence are have no bearing on each other & are independent (in the statistical sense, i.e. the "evidence" is not evidence at…

[deleted]

Re: Can I Be Trusted?

#43
post #30
post #25

Earlier quoted context omitted.

I did read it, and the answer remains the same: > I trust Bruce Schneier to not sacrifice his own principles and belief system in backdooring some code or otherwise compromising his work. To mislead would be to compromise his own work.

That would depend on what his work actually is. If it's to promote the understanding and application of cryptography and security, as we believe it to be, then misleading people would certainly compromise what he does. If, on the other hand, Bruce is an NSA shill, then misleading people would in no way compromise his work - it would be his work. As much as we all might respect Bruce we should remain reasonably open t…

In this context, "his work" could also include password safe: https://www.schneier.com/passsafe.html

It is open source. You are free to inspect it and see if it has backdoors.

Likewise with Twofish: https://www.schneier.com/twofish.html

This is quite the long con if you think he's been developing, advocating and promoting free (as in speech) software for years just in case this NSA thing got out of hand.

I agree we shouldn't let a single expert become a single point of failure in our understanding of security, but that's missing the point in this discussion. Based on Schneier's long history of work, including advocating open source solutions, he's earned my trust, but the great thing is that because he's such an advocate for open source, you can check the code. Likewise, if you're reading something he's written, you can check his sources. You don't have to trust him. You can do your own fact checking!

Re: Can I Be Trusted?

#46
post #43
post #30

Earlier quoted context omitted.

That would depend on what his work actually is. If it's to promote the understanding and application of cryptography and security, as we believe it to be, then misleading people would certainly compromise what he does. If, on the other hand, Bruce is an NSA shill, then misleading people would in no way compromise his work - it would be his work. As much as we all might respect Bruce we should remain reasonably open t…

In this context, "his work" could also include password safe: https://www.schneier.com/passsafe.html It is open source. You are free to inspect it and see if it has backdoors. Likewise with Twofish: https://www.schneier.com/twofish.html This is quite the long con if you think he's been developing, advocating and promoting free (as in speech) software for years just in case this NSA thing got out of hand. I agree we s…

But now you're actually arguing why he _should_ be trusted, rather than just taking it as a matter of faith, which was the whole point of the exercise.

Re: Can I Be Trusted?

#48
Well for one, he uses Windows on his super secure airgapped computer. That must mean he is in bed with the NSA!

The top comment on the site pretty much covers it: trust, but verify.

Re: Can I Be Trusted?

#49
post #48

Well for one, he uses Windows on his super secure airgapped computer. That must mean he is in bed with the NSA! The top comment on the site pretty much covers it: trust, but verify.

Haha. And I use Linux -- and I usually leave SELinux turned on... so my OS is infested with NSA-written software.

(I do think about this sometimes... I guess I just hope that "with enough eyes, all bugs are shallow". I hope.)

Re: Can I Be Trusted?

#50
If the goal of the hypothetically-compromised Bruce Schneier is to reinstate public trust in weak crypto, he's doing an exceptionally bad job.

To the extent that he maintains crypto is still a plausible defense, there's a huge asterisk next to 'crypto' that boils down to: you really can't know whether you've actually got strong crypto. [1]

For anyone who doesn't have a burning interest in privacy or security, for the regular joe on the street, Schneier's collected reporting reads: they won, it sucks, we need to fight back at the ballot box.

[1] Due all his reporting on the NSA: tapping every wire; injecting vulnerabilities and backdoors, whenever possible, in crypto libraries, crypto programs, services, operating systems and hardware; by hook or by crook, having access to just about every vendor and service providers keys and internal data. And if they want into your computer, specifically, Schneier maintains they're basically in. Hardly a reassuring word among them.

Post reply on HN