4 ms·
> needing multiple keys in order to decrypt - not sure if that's mathematically possible As a matter of interest Shamirs Secret Sharing algorithm (https://en.w
by polymatter 11y ago
> needing multiple keys in order to decrypt - not sure if that's mathematically possible
As a matter of interest Shamirs Secret Sharing algorithm (https://en.wikipedia.org/wiki/Shamir's_Secret_Sharing https://en.wikipedia.org/wiki/Shamir's_Secret_Sharing) is quite nice in that respect. The "secret" would be the decryption key. Using Shamirs Secret Sharing algorithm you could split the key into two so you would need both parts in order to work out the decryption key. The government could have a part. The company could have another. Only when both were combined could anyone work out the decryption key.
This would mean neither the company nor the government could decrypt messages until they work together - and therefore reduce the risk of hackers and rogue employees. It wouldn't break the encryption with dangerous backdoors but would allow the authorities to quickly gain access when needed for a specific investigation.
I doubt anyone would ever implement anything like that since it would be (slightly more) complex and you would have to trust that the decryption parts are valid. But I thought I would just mention it in case anyone else might find that algorithm as interesting as I do.
- fossuser 11y agoThat's a cool algorithm - and while it does reduce the risk of a hack succeeding I think it still could be considered a 'backdoor'. It's just a backdoor that requires to people to work together to open, harder to compromise yes - but I'd argue still not really secure. If you have a government entity routinely breaking into companies and taking over access to things (targeting sysadmins) then the scheme doesn't work very well. I think most of the argument behind encryption falls on this idea that it either is secure (no backdoors) or it isn't. You have a spectrum of insecure things you can do that are arguably better than nothing, but they're not secure.