Hacker News new | ask | show | jobs
by xingped 29 days ago
Cool. Everyone's threat model is different. As long as we're not writing passwords on sticky notes attached to the monitor, I don't think there's any need to be throwing stones.
4 comments

> Everyone's threat model is different.

Everyone's threat model is different, but some are better than others, and maybe we shouldn't equate taking time to explain why with throwing stones.

Sensitive data written down on a sticky note is arguably more secure than that same data sitting on an unencrypted hard drive, at least in a home setting.
Hey now, I use rot13 on my sticky notes.
Gotta bump that encryption up - rot26 is twice as secure.
Secure rot* variants require UTF-8 and mappings that shift characters between {1,2,3,4}-byte encoded-character-sizes. That varies the message length, which prevents any message-length or traffic analysis.

The Snowden leaks revealed that the NSA is flummoxed on how to tackle variable character lengths. However, they've cracked rot26 using custom ASIC supercomputers, so it should be considered insecure even though it's twice as good as rot13.

I did not throw a stone, i only clarified my counter position for others to understand why I encrypt.