Patrefans
Surveillance Report from patreon
Surveillance Report patreon

Q&A: Nate's Phone Literally Exploded. What Now?

🕑 Added 2024-09-18 17:00:07 +0000 UTC
Q&A: Nate's Phone Literally Exploded. What Now?
Q&A: Nate's Phone Literally Exploded. What Now?
Q&A: Nate's Phone Literally Exploded. What Now?
Q&A: Nate's Phone Literally Exploded. What Now?

Comments

Apricot

If you were asked to help draft privacy regulations, what regulations would you want to see? Can privacy regulation help protect users who don’t follow best practices (password manager with unique passwords, 2FA)?

David Johnson

Cybersecurity experts often appear to categorically condemn secrecy safeguards that lie outside of ordinary encryption/authentication as "security by obscurity". However, every safeguard seems to boil down to "hiding a needle in a haystack", and is thus vulnerable to users overestimating how big and opaque their "haystack" is, and how hard-to-guess their "needle" is. In other words, people often underestimate the predictability/transparency of their IRL behaviors just as they do with the predictability of their passwords and usernames and other online behaviors. What is your opinion on this subject, and what do you think are good/bad, underrated/overrated safeguards outside conventional encryption/authentication? It is probably far easier to precisely calculate the strength of conventional encryption/authentication than for unconventional safeguards. However, the former can often only be implemented in conjunction with the latter, and it is the latter that seems to be more frequently exploited by attackers (i.e. old-school scam techniques). At the same time, the organisations we consider the most secure in the world make extensive use of "security by obscurity". Moreover, most of the unsolved tantalizing mysteries of history remain mysteries because of "security by obscurity", not because of robust encryption.


More Creators