Hacker News new | ask | show | jobs
by coldtea 1044 days ago
>The mistake you are referring to is someone that assumes "encrypted" means three letter agency safe, which is a pretty terrible way to leverage encryption.

That's not a mistake, that's table stakes. People reading that X offers "encryption", should assume its cryptographically safe to the standards of the day, and be given that.

Not just some "safe from your spouse, ...maybe..." glorified rot13.

Else, just don't offer it. It's not Vim's place to offer "file encryption" anyway, especially if they can't keep that promise. It's fine not to offer it.

And it doesn't have to be a "three letter agency" that's the threat. The "angry ex-girlfriend" could might as well be a programmer. Or have a script-kiddie nephew. Or know a person or two who can use off-the-shelf tools to decrypt it. And the file might have things like a person's bank account passwords.

1 comments

the three letter agencys built modern encryption with explicit loopholes. [0] They probably made bitcoin too.

Thus, the GF V. FBI scenario. Just because you "encrypt" something doesn't make it '100% Safe'. Such as someone keylogging you for your onepass pass.

[0] https://www.washingtonpost.com/graphics/2020/world/national-...