Earlier quoted context omitted.
> It's a false dichotomy. What part of the parent are you responding to here? > Your private keys are just "obscure" information that requires some effort to find too. I think this is highly misleading. There is nothing "just" or "some" about it. Your private keys are "obscured" information that requires a (mostly) specific and quantifiably very large amount of effort to find, and which if it were to become exposed,…
How do you quantify the probability someone will gain unauthorized access to your office? How do you quantify the probability they have a rootkit for your machine?
Re: Hackers Are Emptying ATMs with a Single Drilled Hole and $15 Worth of Gear
#81Well, that's why I said "mostly". The thing I need to protect, the key, is a very specific piece of data, which is used for one specific purpose, and I can take specific measures to prevent that secret from leaking. Everything from not writing it down, to key-sharing, to physical lock boxes with multiple locks, to offline-only storage, etc. It's much harder to do any of that with blueprints, since blueprints have competing needs -- they are no good if locked in a box most of the time.