getodk / getodk/docs

Docs make claim that NSA can break AES

Open
#1,210 0 comments 0 reactions 0 assignees View on GitHub
bad info
Dominant language
Python
Stars
58
Forks
160
Avg merge
5d 11h
Merged PRs (30d)
12

Description

The Security and Privacy guide ([`security-privacy.rst`](https://github.com/opendatakit/docs/blob/master/odk1-src/security-privacy.rst)) makes an offhand claim that the NSA may be able to break AES encryption. Granted, it's impossible to know what orgs like the NSA can and can't do, but I think we should link to something pretty solid if we have that in the docs. Otherwise, maybe we should replace it with a short mention that everything is **technically** crackable (given enough time, computing power) but that AES is considered to be strong enough that no publicly known tech can crack it.

Also fun fact, and this means I get to link to my favourite "post-" after "post-hardcore", but AES is also currently considered to be safe in a [post-quantum world](https://en.wikipedia.org/wiki/Post-quantum_cryptography#Symmetric_key_quantum_resistance).

Contributor guide

Open the contributing guide

Research direction

Open security-privacy.rst and locate the statement about the NSA breaking AES. Review the linked post-quantum reference and verify the claim against a solid public source before choosing the wording. Done means the guide contains a supportable AES security statement with an appropriate reference.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.