Security Nihilism Debate

Discussions debate security nihilism versus incremental security improvements, questioning threat models, imperfect measures, trade-offs, and alternatives like hardware crypto or encryption.

➡️ Stable 0.6x Security
4,398
Comments
19
Years Active
5
Top Authors
#2727
Topic ID

Activity Over Time

2008
13
2009
36
2010
59
2011
85
2012
104
2013
232
2014
218
2015
252
2016
347
2017
294
2018
304
2019
324
2020
322
2021
362
2022
345
2023
367
2024
323
2025
377
2026
36

Keywords

IT WEAKEN HN IS SUPPOSED PRO TLS NSA CA JWT security secure functionality plugin securing threat certificates standard library trade claims

Sample Comments

secfirstmd Feb 13, 2017 View on HN

On what grounds? on what threat models? on what attacks? what alternatives?

eeZah7Ux Mar 18, 2021 View on HN

It's pretty crazy that we don't have something similar now. And possibly with better security.

CamperBob2 Oct 29, 2015 View on HN

I can't think of any other technologies that have waited for the security aspect to be solved, can you?

Tepix Oct 25, 2021 View on HN

Saying you can't be secure at all isn't a solution.https://blog.cryptographyengineering.com/2021/07/20/a-case-a...

staunch Oct 23, 2013 View on HN

Not only does it obliterate users' security but it introduces a potentially unreliable point of failure. Sometimes the hack is worse than the problem it solves. I hope they're being extremely upfront with users about how this works, not that most users will really understand the implications...

WrtCdEvrydy Apr 4, 2023 View on HN

This is good for security overall... think about it, if we sent all of our stuff to the NSA, they would find security bugs and fix them for us.

bigstrat2003 Dec 6, 2023 View on HN

This is an absolutely terrible take. Just because the mechanism doesn't provide perfect security doesn't mean a) it provides none, or b) it isn't even trying to provide security.

cf141q5325 Sep 23, 2023 View on HN

Lack of security is likely working as intended, be it on the system level or with encryption often relying on certificate authorities. Fixing any of this would likely result in the intelligence agency threat scenario of "going dark". Its the brave new world we live in where zerodays are valuable investments for governments.

Krasnol Aug 28, 2024 View on HN

Why wouldn't he make it truly secure by hardening the most used features?They don't even seem to work on it. There is this optional encryption, but nobody seems to care about it. Simultaneously, they present themselves as safe and secure.He might be a genius.He might also be an evil genius.

dumbfounder Aug 7, 2023 View on HN

The fact that they are popular means it's an argument against making a more secure version? You are implying the problem is solved perfectly already. They are popular because they are needed, not because they cannot be advanced.