
Anastasiia Voitova -- Encryption is easy, key management is hard
Om avsnittet
Adding encryption is easy; designing a system that protects keys, metadata, and users is much harder. Anastasiia Voitova joins Chris and Robert to explain end-to-end encryption as a system property rather than a single cryptographic feature. She examines what encryption does and does not protect, how modern web and mobile architectures complicate trust boundaries, and why cloud storage creates difficult key-management choices. The discussion covers performance, recovery, usability, and the gap between marketing claims and honest threat models. Anastasiia closes with practical advice for product and security teams deciding whether end-to-end encryption fits their system and how to communicate its tradeoffs clearly.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Anastasiia Voitova:
→ Anastasiia Voitova on LinkedIn
→ Cossack Labs
Mentioned in this episode:
→ Cossack Labs
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Encryption is easy; key management is hard
02:44 Defining end-to-end encryption
06:28 What end-to-end encryption protects
09:15 Modern web and mobile trust boundaries
12:36 Cloud storage and key-management choices
14:00 The downsides of stronger encryption
16:38 Performance and operational costs
19:01 Usability and honest encryption claims
23:18 Can users trust messaging applications?
27:00 Choosing the right security tradeoffs
30:38 A call to action for product teams
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.