BTW, everyone using the "But lives depend upon this, the CryptoCat author put lives at risk!" argument to excuse Steve Thomas's attacking tone in this article is more or less being a hypocrite.
What about the fact that Steve Thomas, by releasing a tool that makes it extremely easy to decrypt the conversations encoded by CryptoCat at specific times, has done exactly the same thing? Disclosing a vulnerability in this public manner and providing a decryption tool on a platter has probably done more damage to the hypothetical journalists who were hypothetically using CryptoCat.
I don't think bad crypto should be forgiven, but it would be easier and probably less arrogant to just submit a diff / pull request publicly that fixes all of the problems that the author observed, and then have people comment upon it. If the author rejects it, these "you are incompetent" comments can go there.
Arrogant takedowns like this "the author clearly has no effing idea about crypto" make it more difficult for newbies like me to understand and try to work on crypto. What chance do I have if any piece of software I write is going to be destroyed by withering comments like "you're a moron" without mathematically explaining what the problem is and laying out the fixes clearly and positively?
by releasing a tool that makes it extremely easy to decrypt the conversations encoded by CryptoCat at specific times, has done exactly the same thing?
Assuming that cryptocat is used to avoid the monitoring of entire nations, you can be absolutely certain that those with the motivations have long ago cracked this. That is exactly why security professionals get so passionate about this, because they know that bad crypto is literally much worse than no crypto at all -- at least in the latter case you have no illusions.
Cryptocat has been under significant criticism for a long time. For instance-
-and for very good reason. After the farcical story about being investigated by CSIS (which seems laughable, because if there's one thing that government security agencies love, it's bad crypto), this project seems to be held aloft by nothing more than people saying "But he's young and passionate, so give him a chance" -- that isn't credible reasoning for crypto.
What about the fact that Steve Thomas, by releasing a tool that makes it extremely easy to decrypt the conversations encoded by CryptoCat at specific times, has done exactly the same thing? Disclosing a vulnerability in this public manner and providing a decryption tool on a platter has probably done more damage to the hypothetical journalists who were hypothetically using CryptoCat.
I don't think bad crypto should be forgiven, but it would be easier and probably less arrogant to just submit a diff / pull request publicly that fixes all of the problems that the author observed, and then have people comment upon it. If the author rejects it, these "you are incompetent" comments can go there.
Arrogant takedowns like this "the author clearly has no effing idea about crypto" make it more difficult for newbies like me to understand and try to work on crypto. What chance do I have if any piece of software I write is going to be destroyed by withering comments like "you're a moron" without mathematically explaining what the problem is and laying out the fixes clearly and positively?