3 ms·
Yes. More specifically, encrypted data cannot be decrypted without the key. So your choices are: 1. Only the user has their key 2. Someone else has the user'
by nathan_long 8y ago
Yes. More specifically, encrypted data cannot be decrypted without the key.
So your choices are:
1. Only the user has their key
2. Someone else has the user's key
If a company, law enforcement, or anybody else has a trove of everyone's keys, that trove will be extremely valuable to hackers, organized crime, domestic and foreign intelligence, etc, and it will be stolen. Whether we'll know it's been stolen is another question.
- niftich 8y agoThe debate typically continues along the government's right to compel the holder to reveal the key, or to reveal the decrypted message, as a loose analogue of rights of governments, where exists, to compel physical writings or access to a strongbox. If we accept that mechanisms in common use, like warrantful search of physical belongings under the Fourth Amendment of the US Constitution, are legitimate and rightful functions of government, then warrantful key disclosure is a logical compromise that protects the individual's privacy, except when the government compels them with good cause to reveal information. Balancing this with protections against self-incrimination is one complication that's currently playing out.
- pjc50 8y agoMy proposal for this, which I doubt either side would support, I call the "piggybank protocol". It has four key elements: - hardware key storage, iphone/TPM style - mechanism for the manufacturer to authorise key release from a device - important 1: this process should be irreversibly tamper-evident, such as IC "fuses" or one-time PROM. This should be permanently visible in the UI, so it cannot be applied invisibly. - important 2: an obligation on the state to pay for replacement devices which have been compromised in the previous step but not used in court. This is to prevent it being routineised.
- cesarb 8y agoHow would tamper evidence help if the device is stolen? If nobody but me has the device encryption key, and my device is stolen, I can be sure that nobody will have access to whatever data it contains. If anybody else has the device encryption key, however, and the device is stolen, I can no longer know whether anybody else had access to the data, no matter how much tamper evidence the device has.
- nv-vn 8y agoThis may be nitpicky, but I don't think we should use the phrase "rights of the government." It implies that the government has some innate justification for those actions, and I think it leads to a slippery slope whereby we create rights of the collective. For example, if the government has the right to jail people, the jail is there to protect all of us. As a society, that gives us the right to beg for anyone to be thrown into jail "for the good of society." It also gives legitimacy to any government action: if they have a right to throw people in jail, you can't really complain about it when they do so even if they're clearly in the wrong.