this post was submitted on 19 Feb 2024
220 points (97.8% liked)
Privacy
32173 readers
1187 users here now
A place to discuss privacy and freedom in the digital world.
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
Some Rules
- Posting a link to a website containing tracking isn't great, if contents of the website are behind a paywall maybe copy them into the post
- Don't promote proprietary software
- Try to keep things on topic
- If you have a question, please try searching for previous discussions, maybe it has already been answered
- Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
- Be nice :)
Related communities
much thanks to @gary_host_laptop for the logo design :)
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Do encryption in software. History taught us hard lessons about this.
Can you think of some notable examples of hardware based encryption failing?
Besides the actual device dying I mean
https://m.youtube.com/watch?v=beMtNM7nwfQ&t=35m
Here is an alternative Piped link(s):
https://m.piped.video/watch?v=beMtNM7nwfQ
Piped is a privacy-respecting open-source alternative frontend to YouTube.
I'm open-source; check me out at GitHub.
There's no password involved in that demo
That wasn't part of the assignment. ;)
The downside with doing encryption in software is that you can't limit attempts. If you are using a high-entropy key this is fine. But getting users to use high-entropy keys has problems. If there is an HSM integrated into the device you can limit the potential guesses before the key is wiped which is critical without high-entropy keys.
A blog I follow recently had a good post about this: https://words.filippo.io/dispatches/secure-elements/
Of course you are still better off with a high-entropy key and software. But if you trade off too much usability in the name of security you will likely find that your users/employees just work around the security.
Sure you can. Use a memory hard hashing algo
That mitigates the problem but doesn't solve it. If you want unlocking to be <1s and your adversary has 10k times the RAM and can take a month they can make 26 billion guesses. So unless your password is fairly high entropy it is at risk. Especially if they have more resources or more time. PINs are definitely out of the question, and simple passwords too.
Good passwords are important. Always.