Hacker News new | ask | show | jobs
by Sohcahtoa82 2886 days ago
Keep in mind the context of this whole conversation. You suggested one-time pads as a solution to PKI and the problems of OpenSSL's large code base being added to projects that need encryption. I don't know how to put this nicely, but it just shows you really don't know what you're talking about.

Yes, sometimes experts get it wrong. Yes, non-experts can sometimes find solutions that the so-called experts couldn't find. I'm not arguing against those claims.

But suggesting one-time pads as a solution to PKI is like seeing someone on the side of the road with a flat tire and suggesting they refill their gas tank.

1 comments

People have the right to criticize whatever they think is a problem. They don't need to be competent. It's just their applied freedom to think. I just mentioned my lack of interest in crypto to prevent what happened but I'm not surprised that it was useless.

IMHO most people defending HTTPs do that by loyalty because they invested so much time on that and not because they understand all the details of the crypto behind.

My message is just: "It's overcomplicated. I quickly found an alternative. I don't buy the meme".

https://en.wikipedia.org/wiki/Shooting_the_messenger

> My message is just: "It's overcomplicated. I quickly found an alternative. I don't buy the meme".

That's exactly my point though. Your proposed alternative does not solve the problem.

We didn't reject your alternative because we think you're incompetent. We didn't reject your alternative because we think HTTPS is fine.

We rejected your alternative because it DOES NOT SOLVE THE PROBLEM. AT ALL. And rather than admit that, you keep defending a point that nobody is arguing against.

Again. Fallacies and aggressiveness.

You're talking about who and not what because the "what" is proven to be unbreakable. You're dishonest.

Hold up.

Earlier, I asked you a question to try to lead you to understand why your proposal was wrong, and you told me to answer my own questions and called me patronizing.

You continued to defend a point (OpenSSL and PKI have problems) that nobody argued against.

Even now, you keep acting like I'm telling you wrong simply because you admitted you're not into crypto.

And you're calling ME dishonest?

I give up. At this point, I'm quite certain I'm being trolled. Or you think being told you're wrong is a personal attack. In either case, you're not worth my time.

Yes you are. Look at your messages and mines. You're the troll. You use "?" and upper case a lot. I don't. You always try to change subject instead of agreeing on the problem. It's a lack of integrity.

You feel threatened because you invested time in those tools. It's not rational. It's an emotional reaction.

I use question marks because I'm asking questions. By having you consider what the answer would be, it would lead you to understanding why you were wrong, rather than me having to be explicit. It is an attempt, albeit possibly a poor one, to teach you something by getting you to think about it, rather than being told. If you would rather I just tell you why one-time pads don't solve the problems of PKI and the additional code bloat of using OpenSSL, I will gladly do that.

I use upper case because your responses are frustrating me, because you continue to insist that your suggestion is being dismissed simply because you're not into crypto, when I have said over and over that it was dismissed because it is simply not a valid solution to the problem originally brought up.

Your claim that I keep trying to change the subject instead of agreeing on the problem is baffling me. Which problem are you referring to here?