> That's because when it comes to security often theoretical vulnerabilities end up being protocol-destroying vulnerabilities in practice. Security folks are notorious for saying, 'that won't work,' being ignored — and then everyone being surprised when indeed it doesn't work.
we're not talking about protocol destroying bugs, were talking about things firmly in the realm of trade offs between marginal security gains and usability with security folks tending to be far too focused on marginal security gains while loosing sight of the big picture of less then perfect security that people use is better then perfect security that nobody uses.
I.E. ChaCha is better then AES because it is more resistant to side channel attacks among other things, but if you are creating a TLS server and can only choose one algo, you probably want to choose AES because more browsers support it compared to ChaCha and the marginal gains from ChaCha probably don't justify excluding those users that don't support it.
> If there is no central directory of identifiers to public keys, there's no way for a spammer to send spam
If there is no central directory of identifiers to public keys, there's no way my mom will use it to send me anything
I don't think her phone has NFC, it might but she wouldn't know if it did. But I don't always see her in person that often, which means we'd have to wait until we were face to face before we could even try to see if she had NFC etc.
we're not talking about protocol destroying bugs, were talking about things firmly in the realm of trade offs between marginal security gains and usability with security folks tending to be far too focused on marginal security gains while loosing sight of the big picture of less then perfect security that people use is better then perfect security that nobody uses.
I.E. ChaCha is better then AES because it is more resistant to side channel attacks among other things, but if you are creating a TLS server and can only choose one algo, you probably want to choose AES because more browsers support it compared to ChaCha and the marginal gains from ChaCha probably don't justify excluding those users that don't support it.
> If there is no central directory of identifiers to public keys, there's no way for a spammer to send spam
If there is no central directory of identifiers to public keys, there's no way my mom will use it to send me anything