Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In order to treat all data with care, you have to define what you mean by "care." In security we talk about the tradeoffs between integrity, confidentiality, and availability. In terms of integrity, the most careful treatment is to place many signed copies of the data publicly on the internet. This also is the most careful treatment for availability. Of course it is the least careful treatment for confidentiality. But no scheme with any care for confidentiality can match it for integrity and availability.

Signal illustrates swinging far in the "confidentiality" direction - most messaging services don't forget anything you say, while Signal makes it rather hard for you to retain your messages, and also offers ways to delete them automatically. I find it unfortunate there are no secure, open messaging platforms that offer similar integrity/availability guarantees to services like Slack.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: