5 ms·
That is not how the term is defined. Note from the article: >>An encryption backdoor is any method that allows a user (whether authorized or not) to bypass enc
by CryptoPunk 5y ago
That is not how the term is defined. Note from the article:
>>An encryption backdoor is any method that allows a user (whether authorized or not) to bypass encryption and gain access to a system.
Nothing in there about the method having to be covert.
When the Clipper Chip was proposed in the early 1990s, or when governments publicly propose encryption bypasses today, the mainstream news coverage refers to these mechanisms as "backdoors", despite no covert element in it.
- croes 5y agoWhere does it say that the encryption is bypassed?
- danShumway 5y ago> Note from the article The "SSLStore" is not the definitive source on the definition of a backdoor. It's just an EV certificate merchant. Authorization plays a role in whether or not something is a backdoor. It's not a rigid definition because language isn't actually rigid, backdoors are defined in part by whether or not they're expected and wanted by the end-user, which is inherently a fuzzy category. But it's silly to say that any access method authorized or not is a backdoor, by that logic my own encrypted computer hard drive has a glaring backdoor in the form of me knowing the passphrase for it.
- CryptoPunk 5y agoIf you google the term, and find any article on the term, you'll see that it is not limited to access methods that are covert. Here's another top 10 result: https://www.klemchuk.com/ideate/encryption-backdoors-and-balancing-privacy https://www.klemchuk.com/ideate/encryption-backdoors-and-bal... Pubicly proposed interception mechanisms, like the Clipper Chip, were widely referred to as a backdoor, as have those put forth by the UK government recently for encrypted messaging apps https://www.express.co.uk/life-style/science-technology/1556283/uk-government-prepares-to-launch-attack-whatsapp-facebook-messenger-end-to-end-encryption https://www.express.co.uk/life-style/science-technology/1556... >>backdoors are defined in part by whether or not they're expected and wanted by the end-user, This would not be wanted by the end-user. The backdoor in this case is just an imposition on the receiving party, i.e. the merchant, that they'd rather do without. No tool to let the state eavesdrop on or surveil one's private affairs is wanted by the party being subjected to it. This is unequivocally a backdoor, and it would only win out in the market if tools without backdoors are eliminated from the market by the state, using the state's apparatus of violence (the police, courts and prisons that gain compliance with government edicts).
- danShumway 5y ago> If you google the term, and find any article on the term, you'll see that it is not limited to access methods that are covert Random company blogs and random UK news blogs aren't the authorities on what a backdoor is. You look at something like, for example, Wikipedia, and it basically agrees with my take above: backdoors are usually covert, but are intrinsically somewhat fuzzy to define. This is how the word is typically used in common conversation. > This would not be wanted by the end-user. The backdoor in this case is just an imposition on the receiving party, i.e. the merchant, that they'd rather do without. Speak for yourself, this is literally the selling point of GNU Taler, this is one of the reasons people are interested in it. They put "taxable" in the tagline not just out of an interest in transparency but because it's their main "hook" to get people interested in the system. Once again, I talked about this above, but backdoors are a fuzzy concept where different communities can end up with different conclusions about what does or doesn't fall into the category of a backdoor. The fact that you personally don't want income levels for merchants to be auditable by the state does not mean no one else wants that transparency (merchants included). Once again, taking that idea to its logical conclusion would be absurd. A nontrivial number of software merchants would like it if my browser didn't have inspector tools and didn't let me look at the source code of pages that they sent me. A lot of web publishers would like it if browsers didn't have tools that let people intercept and modify HTML before it gets rendered to the page. That doesn't mean my browser inspector or my adblocker is a backdoor. These terms are in part socially defined, and yes, expectation and transparency are a part of how we do that. They're not the only part, but they are a part. You posit a world where any disclosure of any information where anyone would prefer that information to be private is a backdoor, and that broadens the definition of a backdoor beyond the point of usefulness and beyond the scope of how most people and most articles online use the term.
- danShumway 5y agoI guess as just one last note, there's some irony in the fact that you're criticizing Taler for having a backdoor in the form of making revenue to merchant accounts auditable, when Ethereum/Bitcoin record literally all transactions to both sellers and buyers publicly, including not just transaction volume but transaction sources. Yes, you can try to use Bitcoin/Ethereum pseudonymously, but you can also try to use Taler pseudonymously, and yes you can try to mix up your coins to obscure specific transactions, but you can also try to mix up your transactions and do money laundering on Taler too. Basically any privacy measure that Bitcoin tries to add on top of the blockchain to get around its more fundamental privacy problem could also be applied on top of Taler, including things like shared wallets, mixers, transaction rollups, etc... By your definition of what a backdoor is, it seems like Taler is meaningfully less backdoored and meaningfully more private than most cryptocurrencies, including Ethereum. That's especially true once currency/coin exchanges enter the mix.