On Wed, May 30, 2012 at 9:59 PM, Girish Venkatachalam <
[email protected]> wrote:

> Cryptography as a discipline is not easy for anyone to learn.
>
> I remember how poor the knowledge is in the IITM computer science
> department. And also
>  in the industry in Bangalore, Chennai and so on.
>

You would be held in much better light if you do not pass such value
judgements. My interactions with IISc has been good. I reckon IITM would
fall in the same category. Generally speaking, industry would implement
standards chosen by bodies but not research into algorithms - this is
typically the domain of academia. Inspite of this, I've met guys who know
the subject in depth.


> For instance the first thing they say is that secrecy of algorithm is
> not security.
>
> Hiding your ssh port by running it on a different port is not
> security. Changing the greeter of
>  your protocol and changing the signature of certain protocols is not
> security.
>
> Real security comes with doggedness, clean habits, discipline, being
> on top of the alerts and
>  patches and so on and of course running an excellent operating system.
>
> Most of the security loopholes we find are due to the C compiler not
> doing bounds checking
>  causing buffer overflows.
>
> Then you have SQL injection, broken protocols, user auth and so on.
>
> Cryptography can only solve certain issues like ensuring data
> integrity through signatures,
>  confidentiality through symmetric encryption and secure
> authentication using password
>  hashing or some other technique.
>
> For the rest you need other tools.
>
> And usually security is obtained at the cost of convenience.
>
> In an increasingly networked world with social engineering and so on
> with mobile phones
> connected to the web security will continue to be a concern.
>
> People think spam control is also a security topic.
>
> To a certain extent yes.
>
> But core security is mostly about which authentication technique to
> use, how to improve
>  the physical security, data leakage prevention by using a good
> firewall to inspect mail
> traffic and uploads, snort for intrusion detection and so on.
>
> Security is a process and not a product.
>

This whole post is a meandering one and a rant with little connection to
the subject line. There are just a few lines on where crypto is used, but
barely anything worthy of being called an introduction.

I've restrained from posting repartees and I guess so have many to the
inane comments and judgements you assert in your posts. I do not doubt what
you know. If you intend spreading knowledge, do so selflessly without
trashing others.

-- Mohan Sundaram.
_______________________________________________
ILUGC Mailing List:
http://www.ae.iitm.ac.in/mailman/listinfo/ilugc

Reply via email to