Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Good point, let’s switch to unbreakable open source systems based on OpenSSL instead.

This kind of advocacy is not only unhelpful but actually counterproductive



Software encryption is very often much easier to rotate than integrated solutions. When all the TPM chips were broken, Windows stopped using them for BitLocker, but didn't reencrypt any of the affected disks. They're just as vulnerable as they were.


Software encryption is also harder to protect without a trusted boot path. My point was just that this isn't a simple binary decision but rather something which requires review and defense in depth.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: