Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes,

But it seems like the situation they describe is one where you wouldn't want to use encryption at all. Why give the user his data in an encrypted form when you can give the user an ID and keep his data entirely away from him? Seriously, when does giving someone data you don't want them to read ever work better than just not giving them data at all?



I agree. That's why "keep the data on the server" is preferable to "send it to the user but protect it with custom crypto".


Yes,

Having a narrative reinforces the point that what you actually do depends on the entire context of the application. You would almost never be the one implementing cannot-be-broken-under-ANY-circumstances encryption. So you have to know what the circumstances are. In this case, the circumstances point to no-encryption-whatsoever!

Sure, you could point to other circumstances where something like what they're talking about would be useful but that's a million possible circumstances with a million possible encryption solutions and you've lost the useful urgency of the original concrete narrative.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: