Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is an interesting tool, and I'll happily use it for puzzle solving, but I'm concerned that it misrepresents itself in a dangerous way.

From the About link:

> "CyberChef encourages both technical and non-technical people to explore data formats, encryption and compression."

> "It is expected that CyberChef will be useful for cybersecurity and antivirus companies."

From the backing Github readme, which as far as I can see is not directly linked on the page:

> "Cryptographic operations in CyberChef should not be relied upon to provide security in any situation. No guarantee is offered for their correctness."

Now, it's fair to say that professional security types should assume the 'no guarantee' bit. But it's not fair to offer it up as a one-stop-shop for non-programmers to handle encryption tasks, and then offer no caveat at all in the primary reference page. It's even less acceptable when the About page implies the opposite.



Do you use nginx, chromium, bash, openssl, linux...? Because they all have disclaimers with more or less the same meaning. It's boilerplate to avoid liability, not warnings motivated by known shortcomings.


I'm aware, but I think I was unclear - that's what prompted my comment on professionals knowing this already.

My complaint was more that this is another entry in the pattern of handing people black boxes labeled "this does cryptography!", without offering any plain-English explanation of what they're actually getting.

It felt particularly important to me here because it's a comparatively new initiative, and the caveat went on the Readme (seen by users who already know) but not the About (targeting users who might not).


I'm going to chime in to say that I wouldn't give implicit trust to this unless the crypto/hash routines are all using standard/known libraries.

I guess I am paranoid about potential backdoors - something that non-crypto people wouldn't know or understand. Heck - who knows, there could be something in there that even the crypto community could miss...?

In our current world, I don't think my paranoia is misplaced. This project may be perfectly safe, offered transparently and no funny business. But then again, who really knows? Unless you are one of those experts in cryptography (and even then, as I understand it, that doesn't guarantee anything) - there could be subtle changes that could potentially open things up for "bad actors"...

I guess I'm saying "trust but verify"...?



I guess as long as a diff between it's version and this one doesn't pull up anything suspicious...?


> "Cryptographic operations in CyberChef should not be relied upon to provide security in any situation. No guarantee is offered for their correctness."

Fair point, but I'd imagine that's just something that their legal dept. made them put up.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: