Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"military-grade AES encryption"

Can we please, as an industry, agree to stop using bogus terminology like this?

"Even the NSA won't be able to read your dirty secrets"

And can we stop using ~"Our encryption beats the NSA" as a selling point, given that:

1. It doesn't take into consideration the various side-channel attacks the NSA would actually use

2. It's unlikely to be true even discounting side-channel attacks

3. It's a scare tactic at best, akin selling boats that are rated "kraken-proof".



In addition,

«GPG for data at rest. TLS for data in motion. … If you're typing the letters A-E-S into your code, you're doing it wrong.» — Thomas Ptacek

https://web.archive.org/web/20090911032333/http://chargen.ma...


Wasn't that more of "don't implement crypto yourself" than "don't use AES" though?


Indeed. Which carries through to this: If you're telling your users that you use {lower_level_crypto}, either you really mean "we're using GPG", and you should say that, or you rolled your own and you're violating the aforementioned suggestion.


In my defence, I wrote that before Snowden (the events, not the person). In fact I absolutely agree that encryption is probably ineffective if you're trying to hide stuff from a government.

However the main use for encryption is to store your journal on an insecure medium such as Dropbox, and I believe encryption is still the best way to keep your data from companies you don't trust.

(Then again, after Condoleezza Rice got on the board of Dropbox, I'm not so sure anymore.)




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: