LWN.net Logo

Security quotes of the week

Security quotes of the week

Posted Oct 25, 2012 15:36 UTC (Thu) by wahern (subscriber, #37304)
In reply to: Security quotes of the week by tpo
Parent article: Security quotes of the week

Timing attacks are well known and popular crypto libraries like OpenSSL take them into account. Newer algorithms and implementations are designed with timing attacks in mind. (They were known before DJB's paper, but it wasn't until around that time that public proof of concepts were published.)

The fact that cryptographic protocols can be commonly circumvented by bugs and laziness in the employing applications is also not new. But it usually takes proofs of concepts to catch people's attention.

I wouldn't call common protocols security theater. Security theater usually refers to tactics and procedures which are fundamentally insecure, or at least not based in any rigorous methodological science. The characteristics of cryptographic algorithms and protocols, OTOH, are quantifiable, and you can reason about them, including making assessments about the difficulty of their use.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds