3 ms·
The article mentions "tech companies." But isn't SSL end to end encrypted? And doesn't nearly every business that makes transactions online use SSL?
by delish 7y ago
The article mentions "tech companies." But isn't SSL end to end encrypted? And doesn't nearly every business that makes transactions online use SSL?
- kelnos 7y agoTLS (fka SSL) is not really what we mean when we talk about end-to-end encryption; it's client-server encryption. Law enforcement would usually not have a problem with that, as they can present a court order to the operator of the server to secretly siphon off the decrypted data at their end and send it to the government. End-to-end encryption is where the service provider has no ability to decrypt any of the data that passes through their servers. Only the endpoints can do that, which (usually) can't be tapped without the endpoints' knowledge.
- fragsworth 7y agoI assume they'd come up with a new encryption standard where you use an additional (government) public key to encrypt with, allowing the government to decrypt it later? Or maybe they'll only enforce the rules on "chat applications" or things the general public uses? I guess they're talking about this right now.
- delish 7y agoI’m sure you’re right. And I guess I’m saying something obvious when I say they haven’t thought this through. So they’re going to get every bank, every e-commerce website, every server and every client to upgrade their SSL packages? That’s daunting. (that’s ignoring the challenge of never leaking the government’s golden key)