Re: crypto for criminals?

From: Tom St Denis (tomstdenis_at_gmail.com)
Date: 07/02/05


Date: 2 Jul 2005 04:17:18 -0700

Dane Metcalfe wrote:
<snip>

In the real world it's upto the designer to prove their worth.

This guy is layering on various diffrent algorithms all of which have
differing levels of security [some are broken even] in a vain attempt
to say "you have to break all these first".

First off, that's bad engineering. Perhaps it could be secure [I'm not
saying one way or the other without seeing code] but it's also
inefficient. It's the job of a competent cryptographer to not only
address the security needs but also to do so with a minimal use of
resources. In this, he fails miserably.

Second, nowhere on his site does he talk about authentication. So
people can alter files and nobody is the wiser...

At anyrate it's not upto Joe to analyze it. Just to point out the
clear "bad engineering" and infer that it's an amateur job.

Tom