Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I did read it, and the answer remains the same:

> I trust Bruce Schneier to not sacrifice his own principles and belief system in backdooring some code or otherwise compromising his work.

To mislead would be to compromise his own work.



That would depend on what his work actually is. If it's to promote the understanding and application of cryptography and security, as we believe it to be, then misleading people would certainly compromise what he does. If, on the other hand, Bruce is an NSA shill, then misleading people would in no way compromise his work - it would be his work.

As much as we all might respect Bruce we should remain reasonably open to the idea that he can be wrong (maliciously or otherwise). In essence, we shouldn't let a single expert, now matter how good they appear to be, become a single point of failure in our understanding of a complex subject.


In this context, "his work" could also include password safe: https://www.schneier.com/passsafe.html

It is open source. You are free to inspect it and see if it has backdoors.

Likewise with Twofish: https://www.schneier.com/twofish.html

This is quite the long con if you think he's been developing, advocating and promoting free (as in speech) software for years just in case this NSA thing got out of hand.

I agree we shouldn't let a single expert become a single point of failure in our understanding of security, but that's missing the point in this discussion. Based on Schneier's long history of work, including advocating open source solutions, he's earned my trust, but the great thing is that because he's such an advocate for open source, you can check the code. Likewise, if you're reading something he's written, you can check his sources. You don't have to trust him. You can do your own fact checking!


But now you're actually arguing why he _should_ be trusted, rather than just taking it as a matter of faith, which was the whole point of the exercise.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: