flavors of reptile lubricant, was Another Snake Oil Candidate

John Levine johnl at iecc.com
Thu Sep 13 09:45:42 EDT 2007

I always understood snake oil crypto to refer to products that were of
no value to anyone, e.g., products that claim to have secret
unbreakable encryption, million bit keys, or "one time pads" produced
by PRNGs.

What we have here is something else, a product that is reasonable for
one kind of threat, physically losing it, oversold for a threat where
it's not, end to end security.

Seems to me that we need a different term for this category.  Of
course, given the nature of marketing departments, it may well
apply to all crypto products.


