[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[ih] email at scale
> At this point, the entire notion of identity seems to have some very strong requirements for security. And security has become pretty deeply rooted in cryptography, which is obviously an ongoing arms race. So I think you are correct that we are in fact doomed, but should try anyway.
Although the crypto arms race is a factor, I believe that reports of
compromises rarely (if ever?) the result of crypt-breakins.
The dominant arms races are against heuristics -- for detecting malware
-- and human factors of social engineering, insufficient UI design, and
insufficient user diligence such as with passwords.
d/
--
Dave Crocker
Brandenburg InternetWorking
bbiw.net