(评论)
(comments)

原始链接: https://news.ycombinator.com/item?id=43471223

Hacker News 上的一篇讨论帖探讨了端到端加密的实际局限性,尤其是在敏感操作的安全通信方面。帖子标题中提到的原文认为,智能手机应用被批准传输机密信息是不可行的。 一位评论者 (gadilif) 反驳说,现有的消息应用可以通过添加“条件访问”功能来改进。这将基于用户身份(由可信提供商验证)或设备的安全认证来限制对某些聊天的访问,这在企业应用中已经是一种常用的模式。 另一位评论者 (PaulHoule) 告诫不要低估人为错误在操作安全(opsec)中的影响。他们以切·格瓦拉遇刺事件为例,即使是理论上不可破解的加密(一次性密码本)也因使用不当而被攻破,这突显出即使是最强的安全措施,如果用户不遵守最佳实践,也会失效。

相关文章
  • 端到端加密的实际局限性 2025-03-25
  • (评论) 2023-12-01
  • (评论) 2025-03-16
  • (评论) 2024-08-26
  • (评论) 2024-02-05

  • 原文
    Hacker News new | past | comments | ask | show | jobs | submit login
    The Practical Limitations of End-to-End Encryption (soatok.blog)
    11 points by todsacerdoti 1 hour ago | hide | past | favorite | 2 comments










    The author writes "I do not foresee any smartphone app ever being approved for this purpose." (the purpose is 'passing classified information for military operations'), while in fact, I'm not sure I see the issue - all the app (any one of them, including WhatsApp, Signal, etc.) needs to add is what is referred to as 'conditional access' to some chats. Meaning, you can define chats as only authorized for users whose identity is provided by a trusted Identity Provider, or are running on certified devices. This type of security is already implemented in many enterprises, supported by browsers (to some extent, at least), and can be relatively easily be supported by applications. Custom made chat apps already use this (e.g. Workplace Chat, which is used by Meta), and so I'm not sure it's something we won't see supported by other commercial apps messaging apps.


    You can't underestimate how much people will screw up operational security (opsec.)

    Arch-revolutionary Che Guevara was tracked down and assassinated because the NSA cracked his "unbreakable" one time pads which would have been unbreakable if he'd only used them once.

    https://www.kopaldev.de/2022/04/27/cryptography-for-everybod...







    Join us for AI Startup School this June 16-17 in San Francisco!


    Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact



    Search:
    联系我们 contact @ memedata.com