Cryptography Quotes
mrxor.github.io
mrxor.github.io
> These numbers have nothing to do with the technology of the devices; they are the maximums that thermodynamics will allow. And they strongly imply that brute-force attacks against 256-bit keys will be infeasible until computers are built from something other than matter and occupy something other than space.
Full context: https://www.schneier.com/blog/archives/2009/09/the_doghouse_...
> The section on "Thermodynamic Limitations" is not quite correct. It requires kT energy to set or clear a single bit because these are irreversible operations. However, complementing a bit is reversible and hence has no minimum required energy. It turns out that it is theoretically possible to do any computation in a reversible manner except for copying out the answer. At this theoretical level, energy requirements for exhaustive cryptanalysis are therefore linear in the key length, not exponential.
"Cryptography is not magic pixie dust that you can sprinkle on a system to make it secure" -Bruce Schneier [? - couldn't find a good source]
"If you think cryptography will solve your problem, either you don't understand cryptography, or you don't understand your problem." -Roger Needham / Peter G. Neumann
Largest number factorized using quantum computers, if we only count algorithms that can theoretically scale into cryptographic levels, is 21.
Cryptographers love tradition. If we were to use “Andy” and “Barbara” as the principals, no one would believe anything in this chapter. -- Andrew S. Tanenbaum
But cryptographers only love math and “Andy” and “Barbara” are friends of "Alice" and "Bob"!
[1] https://www.schneier.com/blog/archives/2012/09/replacing_ali...
"The purpose of cryptography is to force the US government to torture you."
[1] https://www.brainyquote.com/quotes/benjamin_franklin_162078
— Bruce Schneier
I respectfully disagree... <g>
"There are three (3) kinds of cryptography in this world: cryptography that will stop your kid sister from reading your files, cryptography that will stop major governments from reading your files, and finally, the strongest cryptography -- cryptography that will stop Bruce Schneier -- from reading your files." <g>
(Bruce Schneier = Cryptography's Chuck Norris...<g>)
((And the third such cryptography, if it exists... will be found to have been created by -- you guessed it -- Bruce Schneier! <g>))
I will add this comic strip.
My only suggestion would be adding: "Crypto is like catnip for programmers."[1]
[1] https://blog.pinboard.in/2013/04/the_matasano_crypto_challen...
[1]: https://en.wikipedia.org/wiki/Rubber-hose_cryptanalysis
I add XKCD Comic about rubber-hose and Black-bag cryptanalysis[1].
> — Adi Shamir
Source/context for this quote? I do find myself agreeing, but as this seems somewhat more atypical view I'd love to read more about it. Best source I found was this short article about RSA2007 conference, but I couldn't find the referenced panel discussion recorded or transcribed anywhere.
https://www.zdnet.com/article/rsa-2007-keynotes-notable-quot...
Overall I think these sorts of quote collections would be massively more useful if they'd contain verifiable sources.
[1] https://en.wikipedia.org/wiki/Advanced_persistent_threat
>> You voice is always heard - NSA.
That made me chuckle.