5 ms·
Encryption backdoors are not exclusively covert: https://www.thesslstore.com/blog/all-about-encryption-backdoors/ https://www.thesslstore.com/blog/all-about-en
by CryptoPunk 5y ago
Encryption backdoors are not exclusively covert:
https://www.thesslstore.com/blog/all-about-encryption-backdoors/ https://www.thesslstore.com/blog/all-about-encryption-backdo...
This is a backdoor, and puts to a lie the idea that this is in any way "anonymous". It's a tool of the state, to further centralize power around it.
- samhw 5y agoBackdoors are covert by definition. You're talking about an avowed feature you don't like. There's a difference (and finding some random blog post that makes the same mistake is not a proof of anything).
- CryptoPunk 5y agoThat is not how the term is defined. Note from the article: >>An encryption backdoor is any method that allows a user (whether authorized or not) to bypass encryption and gain access to a system. Nothing in there about the method having to be covert. When the Clipper Chip was proposed in the early 1990s, or when governments publicly propose encryption bypasses today, the mainstream news coverage refers to these mechanisms as "backdoors", despite no covert element in it.
- croes 5y agoWhere does it say that the encryption is bypassed?
- danShumway 5y ago> Note from the article The "SSLStore" is not the definitive source on the definition of a backdoor. It's just an EV certificate merchant. Authorization plays a role in whether or not something is a backdoor. It's not a rigid definition because language isn't actually rigid, backdoors are defined in part by whether or not they're expected and wanted by the end-user, which is inherently a fuzzy category. But it's silly to say that any access method authorized or not is a backdoor, by that logic my own encrypted computer hard drive has a glaring backdoor in the form of me knowing the passphrase for it.
- CryptoPunk 5y agoIf you google the term, and find any article on the term, you'll see that it is not limited to access methods that are covert. Here's another top 10 result: https://www.klemchuk.com/ideate/encryption-backdoors-and-balancing-privacy https://www.klemchuk.com/ideate/encryption-backdoors-and-bal... Pubicly proposed interception mechanisms, like the Clipper Chip, were widely referred to as a backdoor, as have those put forth by the UK government recently for encrypted messaging apps https://www.express.co.uk/life-style/science-technology/1556283/uk-government-prepares-to-launch-attack-whatsapp-facebook-messenger-end-to-end-encryption https://www.express.co.uk/life-style/science-technology/1556... >>backdoors are defined in part by whether or not they're expected and wanted by the end-user, This would not be wanted by the end-user. The backdoor in this case is just an imposition on the receiving party, i.e. the merchant, that they'd rather do without. No tool to let the state eavesdrop on or surveil one's private affairs is wanted by the party being subjected to it. This is unequivocally a backdoor, and it would only win out in the market if tools without backdoors are eliminated from the market by the state, using the state's apparatus of violence (the police, courts and prisons that gain compliance with government edicts).
- danShumway 5y ago> If you google the term, and find any article on the term, you'll see that it is not limited to access methods that are covert Random company blogs and random UK news blogs aren't the authorities on what a backdoor is. You look at something like, for example, Wikipedia, and it basically agrees with my take above: backdoors are usually covert, but are intrinsically somewhat fuzzy to define. This is how the word is typically used in common conversation. > This would not be wanted by the end-user. The backdoor in this case is just an imposition on the receiving party, i.e. the merchant, that they'd rather do without. Speak for yourself, this is literally the selling point of GNU Taler, this is one of the reasons people are interested in it. They put "taxable" in the tagline not just out of an interest in transparency but because it's their main "hook" to get people interested in the system. Once again, I talked about this above, but backdoors are a fuzzy concept where different communities can end up with different conclusions about what does or doesn't fall into the category of a backdoor. The fact that you personally don't want income levels for merchants to be auditable by the state does not mean no one else wants that transparency (merchants included). Once again, taking that idea to its logical conclusion would be absurd. A nontrivial number of software merchants would like it if my browser didn't have inspector tools and didn't let me look at the source code of pages that they sent me. A lot of web publishers would like it if browsers didn't have tools that let people intercept and modify HTML before it gets rendered to the page. That doesn't mean my browser inspector or my adblocker is a backdoor. These terms are in part socially defined, and yes, expectation and transparency are a part of how we do that. They're not the only part, but they are a part. You posit a world where any disclosure of any information where anyone would prefer that information to be private is a backdoor, and that broadens the definition of a backdoor beyond the point of usefulness and beyond the scope of how most people and most articles online use the term.