The software development community has a naysayer problem
https://iain.rocks/blog/the-software-development-community-has-a-naysayer-problem
I have some commentary about this article to share. Before you read my commentary you need to understand the meaning of 'marmaluke'. Really.
"... the entire point of the layered encryption is that you make it a lot harder to know when you’ve cracked the first layer."
We've gone over this idea many years in the past. The gatekeeper community ain't havin' it.
"Security via obfuscation in encryption? We’re done here. ..... “Hiding what you’re doing in encryption doesn’t make it any more secure.”" .... I got this response many times. Many people seem to fail to understand that encryption is literally obsfucating the data. You’re changing the data so people can’t understand it, and it can be un-obfuscated, aka decrypted which is the entire point. ..... The number of people who called this concept security via obscurity is shocking. It’s a new concept, but just because it’s a new idea doesn’t mean the point of it is to be obscure."
The author is right and wrong.
This is not the first time anyone has proposed the idea of chunking up encryption and cascading ciphers. He is mistaken about that claim.
However he is right about 'security through obscurity' and I will explain why.
The parrots love to shout about "Kerkchoff's Principle", which they say is a truism that security through obscurity is either bad or is not security at all. And this is a lie. The reason it is a lie is because that is not what Kerkchoff said. They have inverted Kerkchoff's Principle to read: "You must disclose the algorithms, or else you are playing security dice." This is totally false.
If obscurity of the method had no effect on security, then classified secrets would be pointless. Classified weapons would be pointless. Classified operations would be pointless. Hiding your location from a stalker would be pointless. If obscurity did not boost operational security, then every police detective would call the criminals in advance to let them know they are being investigated. The military would publish battle plans in advance on the six o'oclock news since 'security through obscurity' is bad.
Kerckhoff’s Principle states that security should not be dependent on the secrecy of the cipher but rather on the secrecy of the key. It is not a mandate to declare which cipher is being used. That is just stupid. Yet some 'cryptography experts' define it this way because they don't know what the hell they are talking about.
If I use a basket of ciphers, and choose a random cascade of them in a random order, that random choice is part of the key schedule, and obscuring the choice of ciphers DOES increase the mathematical hardness and security of the ciphertext. This is what the amateur author is instinctively grasping, and his detractors are wrong, and criticizing the wrong things for the wrong reasons. Without realizing it they are doing the bidding of gatekeepers who don't want widespread cascade ciphers because they require much more time and resources to crack. Just have a look at the recent drama at the crypto standards group trying to remove fallback ciphers in KEM system standards. The gatekeepers don't want us using baskets of ciphers. They want everyone using the same standard, singular lock model on every treasure chest.
Yes, satan's little helpers love to shoot everyone down to make them fall in line with the gatekeeper agendas. These marmaluke parrots and popinjays have no idea that their 'thought leaders' are nowhere near as competent as they portray themselves. In order to keep the illusion going, they try to put others down to ensure their idols remain higher than and aloft over the crowd. Singular people are smart. Put a whole crowd of smart people in a [chat] room or forum and they all get dumb really quickly. IQ addition is a lossy operation.
Who cares that an amateur is experimenting and learning? What kind of dinkus tries to shout that down? What kind of maroon always has to jump in with unproductive whataboutery instead of playing along and helping improve the game play? An authoritarian marmaluke, that's what kind. It seems a lot of jackasses who over-rate their own knowledge ... want to use negativity and boundary policing to prevent the curious from exploration.
"This is probably the best example of how bad the software community actually is. It was a bunch of naysayers who GCHQ called “Script Kiddie cybersecurity experts” because they were just parroting things they’ve heard about security without truly understanding them."
He gets it. Don't cave to the naysayer marmaluke parrots. I say more power to the curious. Let them try and fail and try and fail as many times as they have the grit to bear. That is how we learn to walk, run ... and fly.
I do think some of the author's conclusions are mistaken, such as GCHQ finding his idea 'new' or 'useful', since they have actually used these kinds of cascades and segmented, fractionated, and 'railfence' ciphers since WW1. But let him figure that out and give him ideas to arrive at the right conclusions instead of parroting wrote social rules and mores that aren't even being correctly described.
If you are an ideological boundary cop, you are an enemy of basic humanity. Go away thought cop. Let the curious thrive, and live, and die as explorers.
#cryptography #cryptology #ciphers #encryption #naysayers #freethinkers #curiosity #marmalukes #gatekeepers #gatekeeping #math #cybersecurity #security
Copy the post URL and paste it into the search field of your favourite Fediverse app to reply, repost, or like it.