On how a trivial implementation error (one we're familiar with already) in Debian's OpenSSL means that any message signed with Debian OpenSSL DSA reveals private keys. That's a micro-error; Debian and OpenSSL may have got almost everything else right, but fucked up one tiny detail, and now exposing the ciphertext of certain messages leaks your private key.
This isn't crypto-geek chauvinism. If crypto isn't a big part of what you do in your day-to-day, you're just not going to get this stuff right. That may be the point Jeff is actually trying to make (and the reason he isn't offering a neat solution in his article), but look at the comments on how to "do it right", and you can see that isn't the message that's getting transmitted.
There's a much bigger flaw in Atwood's cryptosystem than has been discussed here --- forget CBC --- but I'm not going to post it, because it will just result in 20 comments about how easy that is to fix, and here's 15 crazy heuristics to do it, so nyah!
http://news.ycombinator.com/item?id=615446
On how a trivial implementation error (one we're familiar with already) in Debian's OpenSSL means that any message signed with Debian OpenSSL DSA reveals private keys. That's a micro-error; Debian and OpenSSL may have got almost everything else right, but fucked up one tiny detail, and now exposing the ciphertext of certain messages leaks your private key.
This isn't crypto-geek chauvinism. If crypto isn't a big part of what you do in your day-to-day, you're just not going to get this stuff right. That may be the point Jeff is actually trying to make (and the reason he isn't offering a neat solution in his article), but look at the comments on how to "do it right", and you can see that isn't the message that's getting transmitted.
There's a much bigger flaw in Atwood's cryptosystem than has been discussed here --- forget CBC --- but I'm not going to post it, because it will just result in 20 comments about how easy that is to fix, and here's 15 crazy heuristics to do it, so nyah!