Keys Not Included: recovering the signing keys for US driver's license barcodes
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
Keys Not Included: recovering the signing keys for US driver's license barcodes
Unofficial Hacker News client; not affiliated with Y Combinator.
bzmrgonz · · focus · HN ↗
morsch · · focus · HN ↗
It's not like non-technical people understand asymmetric cryptography. Or even technical people, for that matter.
Maybe we should refer to the public key as an address, and the private key is just a password again. You can send stuff, securely, to an address. And you can verify the sender when you have their address (ie check the signature).
fragmede · · focus · HN ↗
danw1979 · · focus · HN ↗
I don’t think there’s any process or entity in the physical world that is reasonably familiar to most people that is even remotely suitable as an analogy to public key cryptography.
tialaramex · · focus · HN ↗
These are not analogs to things ordinary people had already seen. For Computation we just got used to it being everywhere and so we don't need to explain it so much.
raddan · · focus · HN ↗
I think the reason we (the HN crowd) don’t like it is that the analogy starts to break down when you start thinking through all of the operations you can do with public keys. But this does not matter much for somebody learning to use them for the first time. I’ve had to grow comfortable with the idea of giving people imperfect explanations so that they can build an intuition. Once that happens I can return with the mathematics so that they can really understand what is going on.
faxmeyourcode · · focus · HN ↗
Reubachi · · focus · HN ↗
IE; the existence of the asymetry allows for the public key to function more than just a "lock", but a much more easy to rationalize "signer attestation.
TeMPOraL · · focus · HN ↗
The analogy doesn't make sense because it's skipping the existence of the third thing that's the actual (pad)lock - the encryption/decryption software. And it does that because it wants to talk about data as having the property of being "locked", which makes no sense in the first place, but that one isn't immediately obvious.
The whole analogy of locks and keys fundamentally makes no sense when talking about data, because locks are external devices, attached to or directly containing the protected thing, while encryption is the process of scrambling the very thing being protected.
All confusion stems from this bad choice of analogy, trying to "make it simple" for the normies.