Hacker News new | ask | show | jobs
by CiPHPerCoder 3317 days ago
If your application-layer cryptography protocol is not secure in isolation, what argument do you have against making it secure in isolation?
1 comments

I have none. I'd merge a sensible pull request.

But characterising it as a huge security flaw is disingenuous. It's neither here nor there.

I'm characterizing it as a protocol/design flaw in something that bills itself as the most secure X, sure, but I haven't done anything to describe it as "huge".

Are you being needlessly defensive?