Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The correct default answer is encrypt after compress.

"Don't compress at all" doesn't help you if you need to reduce bandwidth.

What good is a secure channel if no one uses it because of its high bandwidth requirements?



A lot, possibly a majority, of the major breaks in crypto systems (certainly the interesting ones) in the past decade have been because of compressing before encrypting. If someone wants to compress first, demand that they justify the reduced bandwidth usage.


The interview in the article is for a security position. You answer is incorrect in that situation.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: