1 |
On Saturday 28 November 2009 05:50:42 »Q« wrote: |
2 |
> On Sat, 28 Nov 2009 00:57:54 +0200 |
3 |
> Alan McKinnon <alan.mckinnon@×××××.com> wrote: |
4 |
> |
5 |
> [about LastPass] |
6 |
> |
7 |
> > What I find incredible is that people will accept the site's say-so |
8 |
> > that the site admins can't read the data. They have not proven |
9 |
> > anything, merely asserted something. |
10 |
> > |
11 |
> > The only way to do give that guarantee is to encrypt the data. Which |
12 |
> > then needs a key. Someone must keep the key and it's either you or |
13 |
> > them. If it's them, they can decrypt the data (same reason as DRM is |
14 |
> > doomed to failure) and if it's you - well if you lose the key you |
15 |
> > lose the data. |
16 |
> > |
17 |
> > Are you telling me that there are people gullible enough to actaully |
18 |
> > fall for that one? |
19 |
> |
20 |
> They claim that the decrypted data never leaves your computer and they |
21 |
> they don't have a key to it. Many, many things aren't clear, such as |
22 |
> what kind of encryption is used (same as the US gov't uses for "Top |
23 |
> Secret" stuff, they say, heh), where and how the key is stored on your |
24 |
> machine, on and on. I wouldn't dream of using them, but yeah, they have |
25 |
> a substantial number of users. |
26 |
|
27 |
I have an alarm system in my head. It's called the "Security by bullshit |
28 |
baffles brains Alert". It's ringing right now ;-) |
29 |
|
30 |
Mind you, I have vendors who use exactly the same throw-around-bullshit- |
31 |
statements-and-see-what-sticks approach. It works on the Account Managers all |
32 |
the time, and works on us techies none of them time. |
33 |
|
34 |
Lucky for us, techies rule around here. We get to tell the Account Managers |
35 |
that the vendor is talking crap, that we don't have to explain why, that we |
36 |
are not buying their crap and we are not using it, so please tell the vendor |
37 |
to leave the building and stop wasting my time :-) |
38 |
|
39 |
-- |
40 |
alan dot mckinnon at gmail dot com |