2 ms·
> You would also make the master keys expire regularly (maybe daily) so as long as a user updates their phone they will get updated with the new keys to protect
by Sacho 9y ago
> You would also make the master keys expire regularly (maybe daily) so as long as a user updates their phone they will get updated with the new keys to protect against a leaked key.
What would the logistics of this be? Would the government need to store all master keys to be able to decrypt an old message? How would you know you're using the right key to decrypt a message? What happens if all the old keys leak?
What about foreign communications? You can't compel foreign actors to encrypt with your algorithm. What if I'm storing foreign data which is encrypted with illegal algorithms, is that going to be illegal? If so, then goodbye hosting services in the US. If not, how are you going to differentiate between foreign data and local data?
What about the transition period? What do you do with legacy encryption? What about people who haven't received the newly updated government-sanctioned encryption yet? What about old devices that can't run your encryption algorithm, closed systems, etc?
I don't think it's as incredibly simple as you put it.
- saas_co_de 9y agoWe are talking about different things. I was talking about allowing access to encrypted data on devices which is the main issue that le has been complaining about. You seem to be talking about a backdoor for all crypto everywhere which is very different.