Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That's not how we approach security. We don't think in terms of 'Trust' in algorithm. We think in terms of risk management. It's not uncommon for new algorithms and approaches to have algorithmic or implementation flaws. That is a risk. One of the mitigations we often consider is adding another layer of defense.


Whose is "we", because for example, the DoD doesn't agree with you. It's very much either crypto is "trusted" or useless.

See NIST with the whole FIPS-142/3 debacle where they outright state that "non-certified" crypto is no better than plaintext.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: