Docs make claim that NSA can break AES
- Dominant language
- Python
- Stars
- 58
- Forks
- 160
- Avg merge
- 5d 11h
- Merged PRs (30d)
- 12
Description
The Security and Privacy guide ([`security-privacy.rst`](https://github.com/opendatakit/docs/blob/master/odk1-src/security-privacy.rst)) makes an offhand claim that the NSA may be able to break AES encryption. Granted, it's impossible to know what orgs like the NSA can and can't do, but I think we should link to something pretty solid if we have that in the docs. Otherwise, maybe we should replace it with a short mention that everything is **technically** crackable (given enough time, computing power) but that AES is considered to be strong enough that no publicly known tech can crack it.
Also fun fact, and this means I get to link to my favourite "post-" after "post-hardcore", but AES is also currently considered to be safe in a [post-quantum world](https://en.wikipedia.org/wiki/Post-quantum_cryptography#Symmetric_key_quantum_resistance).
Contributor guide
Research direction
Open security-privacy.rst and locate the statement about the NSA breaking AES. Review the linked post-quantum reference and verify the claim against a solid public source before choosing the wording. Done means the guide contains a supportable AES security statement with an appropriate reference.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 48/100