I'm as arrogant as the worst of them, but this sounds borderline ridiculous.
That said, I'm looking forward to see how you're looking to change this.
I'm as arrogant as the worst of them, but this sounds borderline ridiculous.
That said, I'm looking forward to see how you're looking to change this.
As long as they have a basic understanding of how SSH, GnuPG, and SSL function and a thorough understanding of how to use them that's probably the extent of the cryptographic expertise required.
I think it's wise to avoid "grading" on specific technical questions about things that aren't actually required for the position.
That doesn't mean you shouldn't look for bonus knowledge, but I don't think it's good to be too specific about what it is.
Seriously in the back of my head I heard my Father's voice: "You done fucked up good, boy"
EDIT FOR FATHER QUOTE
Asymmetric encryption has two parts, a private key and a public key. One encrypts data with a public key and then the only key that can decrypt it is the private key. The private key, as the name suggests, has to stay private and is a secret, whereas your public key you can hand out as you please.
In symmetric encryption you have a single key, it is used to both encrypt and decrypt the data, and thus if that single key were to fall into the wrong hands that person could then decrypt the data, whereas with a public key that is not the case.
This is a very simplified overview of the differences.
And even in the post, there are more factual errors... Ctrl+D doesn't ask a program to quit. How can you use Linux for 10+ years and not know why kill -9 is "force" and what the difference is from normal kill?
My brain thought "hm, 1999, now it's 2011, so add 10 to the 1900's to get 2000's, then add 10 more to get 2010's => 20 years".
I always find it interesting to post-mortem my logical blunders.
But sadly, the point stands regardless.
If he understands how PKI works. If he understands that people share a public key which is in turn paired with a private key. And if he understands that said private key is the only key capable of decrypting messages that were encrypted using the public key, that should be fine.
If he knew that much, he'd probably be able to reason out what 'symmetric' vs 'asymmetric' meant, if given enough time.
Is knowing the exact terms better? Yes.
Is it shameful to understand the concept pretty well without knowing every bit of terminology used to describe it? I'd say no.