That made reading the article worthwhile for me.
I mean, what else is a secret but informational asymmetry?
That made reading the article worthwhile for me.
I mean, what else is a secret but informational asymmetry?
It's more like being able to teleport all the keys in all the houses from under the doormat to under a rock in the garden once you notice thieves are checking the doormat. This would, in fact, appreciably increase house security on average, while still being STO.
If you use a 128 bit key, but use a non-time-constant compare somewhere, then it's pretty darn easy to find the needle.
This is why the JPEG fingerprinting example from TFA doesn't qualify to be in the same category as a properly secured cryptographic key. They can notice that non-picture posts are not blocked, but picture posts are, which already greatly narrows it down. They could post a picture generated from the actual client, and see it go through, and narrow it down even more. That's not even that hard of a one for an attacker to figure out. It's much closer to "key under doormat" than "random key"
What I mean is informational asymmetry frames security within engineering practice, though perhaps at a price of winning the internet.
YMMV.