| > all security is just obscurity, eventually, where you are obscuring your private key's semi-prime's factors. This is a lazy take that obscures the definition to uselessness. It’s perpetuated by people who make insecure systems that break when the algorithm is known. There is a vast gulf between: - security depends on secret algorithm - security depends on keeping a personal asymmetric key secret The latter is trivial to change, it doesn’t compromise the security of others using the scheme, and if it has perfect forward secrecy it doesn’t even compromise past messages. Please don’t repeat that mantra. You’re doing a disservice to anyone who reads it and ultimately yourself. |
Understanding the differences that you outlined is so basic that a good commenter wouldn't assume they don't know the difference, they are making a deeper point.