3 ms·
How do you have secure encryption with proprietary backdoors? Maybe this will wake people up to only using open source operating systems.
by braderhart 9y ago
How do you have secure encryption with proprietary backdoors? Maybe this will wake people up to only using open source operating systems.
- ISL 9y agoAny encryption scheme with a backdoor is insecure, by definition.
- gizmo686 9y agoNot if you change the security definition. Which they will. All they are asking for is some form of key escrow; which can (and has) been given a reasonable security definition. The problem is that secure implementations of key escrow are much harder; and (given the amount of use the escrowed key will get), certainly going to be broken in practice.
- braderhart 9y agoDo you have examples?
- ajross 9y agoAndroid, at least the parts that would be required to be modified to implement this misfeature, is already open source. That won't help. The DoJ isn't asking for proprietary code secrecy, fundamentally they're asking for key escrow. Storing data in different places isn't something source visibility can address.
- forapurpose 9y ago> Maybe this will wake people up to only using open source operating systems. OS security has limited impact when other subsystems, not in control of the OS, run on the device.
- braderhart 9y agoDo you have examples and agreed that things like forcing Intel ME do not help, but please note that many of these partially rely on proprietary Windows drivers.
- PrivacyPro1 9y agoLinux has never been hacked. By gosh, you're right!