Gentlemen, please, let's get back on topic
cheers
H


----- Original Message ----
From: Patrick Cahalan <[EMAIL PROTECTED]>
To: [email protected]
Sent: Tuesday, August 5, 2008 11:03:01 AM
Subject: Re: [FDE] software defense for "cold boot" attack?

> I have no idea of the merits of the work in dispute, but in general 
> trashing other bright people's work *is* necessary.  There is much 
> too much garbage, and not nearly enough ridicule.

Dissecting problems with theories is great, especially in the security
related fields.  I agree, more robust argument is generally needed.
Ridicule, however, should be reserved for the ridiculous.

Any marginally complex theory is going to have areas of possible
weakness.  Focusing criticism on the weak areas strengthens the theory
by allowing it to develop, grow, and accommodate areas the original
theorist may not have included in their analysis.

Nobody thinks of everything.

Claiming the overall theory is worthless due to a weakness is usually
not constructive.  Whether or not this is the intention, ridicule often
results in either (a) dismissal of some things that are actually
important in the original theory or (b) castigation of the person
employing ridicule for being an ass without addressing the underlying
argument.

In either case, the overall community loses.

> With a bit more nastiness in the air, we might not have seen the Wifi
>  debacle where the committee issued a broken spec, then fixed it with
>  an equally broken spec, then abandoned compatibility to issue a spec
>  which is *still* broken in that offline dictionary attack is
> possible and usually succeeds.

If we want to solve this problem, we need to make sure committee
composition reflects the desired outcome, instead of sweeping
externalities under the rug.  A bit more nastiness probably wouldn't
have done anything to prevent the problems your alluding to here; when a
committee is made up of a majority of agendas who don't care about
security, you're going to get insecure specifications.

_______________________________________________
FDE mailing list
[email protected]
http://www.xml-dev.com/mailman/listinfo/fde



      
_______________________________________________
FDE mailing list
[email protected]
http://www.xml-dev.com/mailman/listinfo/fde

Reply via email to