Gentlemen, please, let's get back on topic cheers H
----- Original Message ---- From: Patrick Cahalan <[EMAIL PROTECTED]> To: [email protected] Sent: Tuesday, August 5, 2008 11:03:01 AM Subject: Re: [FDE] software defense for "cold boot" attack? > I have no idea of the merits of the work in dispute, but in general > trashing other bright people's work *is* necessary. There is much > too much garbage, and not nearly enough ridicule. Dissecting problems with theories is great, especially in the security related fields. I agree, more robust argument is generally needed. Ridicule, however, should be reserved for the ridiculous. Any marginally complex theory is going to have areas of possible weakness. Focusing criticism on the weak areas strengthens the theory by allowing it to develop, grow, and accommodate areas the original theorist may not have included in their analysis. Nobody thinks of everything. Claiming the overall theory is worthless due to a weakness is usually not constructive. Whether or not this is the intention, ridicule often results in either (a) dismissal of some things that are actually important in the original theory or (b) castigation of the person employing ridicule for being an ass without addressing the underlying argument. In either case, the overall community loses. > With a bit more nastiness in the air, we might not have seen the Wifi > debacle where the committee issued a broken spec, then fixed it with > an equally broken spec, then abandoned compatibility to issue a spec > which is *still* broken in that offline dictionary attack is > possible and usually succeeds. If we want to solve this problem, we need to make sure committee composition reflects the desired outcome, instead of sweeping externalities under the rug. A bit more nastiness probably wouldn't have done anything to prevent the problems your alluding to here; when a committee is made up of a majority of agendas who don't care about security, you're going to get insecure specifications. _______________________________________________ FDE mailing list [email protected] http://www.xml-dev.com/mailman/listinfo/fde _______________________________________________ FDE mailing list [email protected] http://www.xml-dev.com/mailman/listinfo/fde
