Todd Pattist wrote:
Tim Newport-Peace ] wrote:
It was suggested:
A: All Purposes including World Records.
B: Badges and Diplomas
D: Badges up to Diamond
What is the rationale for distinguishing between levels B
and D? If I understand correctly, D was initially separated
from everything else because of concerns about cheating,
then B was shown to be hackable (Wedekind). If that's
correct, why wasn't B moved into group D? Or, more
preferably, why isn't D given the same privileges as B?
Instead of ratcheting up costs, why can't we just use our
Official Observers to control cheating? We relied on them
for decades before RSA/DSA and public/private key
encryption. If I hack an A level recorder (with a GPS
transmitter simulator and a pressure chamber or by opening
the case and inserting GPS code between the off-the-shelf
GPS receiver and the custom circuitry), can we just agree
that no security is perfect and group them all as imperfect,
but usable for all levels with appropriate monitoring by an
OO?
Todd Pattist - "WH" Ventus C
(Remove DONTSPAMME from address to email reply.)
I think the kind of hacking addressed by the change is merely
post download hacking, i.e. patching the downloaded file
and making it valid either because it doesn't have a cryptogrhic
signature or because the method used to generate the signature
is to weak and so the signature can be hacked/faked.
|