4 ms·
The point is that today, the key isn't in Google's or Amazon's or Meta's servers, but on the phones of people. That means that you literally don't have the key
by DexesTTP 3y ago
The point is that today, the key isn't in Google's or Amazon's or Meta's servers, but on the phones of people. That means that you literally don't have the key if you don't have the phone. And governments don't want that, they want the keys in order to eavesdrop but without being noticed (and stealing the phone would get you noticed).
So your only option to comply with this is to remove the phone-only key storage option and move all of the key into your servers, which is what we talk about when we mean "breaking end-to-end encryption".
The issue is that to comply with the rules, you have to secure that server so only the good guys can get in, and only if the warrant is legit, but also to allow fast access for time-sensitive cases such as terrorism and secret cases such as NSA investigations. You also have to make sure that there's absolutely no way for people to access that server if they don't have the approval.
Oh, and also that server / these servers contain the keys to read every message from every citizen of your country (including politicians), which is probably worth as much of your GDP.
So you need to build the equivalent of a safe containing one trillion dollars that can't be accessed for any reason except all of the reasons mentioned abov3. Except that this theoretical trillion of dollars are special dollars where if you mess up and let people in without anyone noticing they got in, they can "steal" the trillion dollars and start spending them and nobody would notice that they're being spent. And there's just about every country on earth that would love to "borrow" your two trillion dollars, especially if you can't ever realistically prove they did it.
Easy, right?
- ethbr1 3y agoHas there ever been a public key sign-countersign encrypted tap method? I.e. Authorized tap requestors have keys (law enforcement, intelligence) and sign a request (including timestamp), storing a copy for audit. The approval system (courts, FISA) validates that request, countersigns if they approve (including timestamp), storing a copy for audit. The system owners (messaging services, etc.) then validate both signatures and provide the requested tap information, creating a tap record (including content scope and timestamp), storing a copy for audit. Ideally, then all audit logs get publicly published, albeit redacted as needed for case purposes. Part of the central issue is deciding "Who should be responsible for security?" Imho, if governments want to mandate a scheme like this, it sure as shit shouldn't be the tech companies. The government should have to manage its own keys, or deal with consequences of leaking them (while allowing the tech companies to retain independent records of individual requests). As much as it pains me to say this... this wouldn't be the worst use case for a blockchain...
- EGreg 3y agoSomething like this? https://community.qbix.com/t/balancing-privacy-and-accountability/215 https://community.qbix.com/t/balancing-privacy-and-accountab...
- ethbr1 3y agoYes! Exactly like what you've apparently thought about and worked on for a long time. Neat! >> To decrypt it, multiple parties need to come together and combine their keys, all the while creating an audit log of why they are accessing this or that portion. To me, this is the technical solution that best mirrors the ideals of the pre-technical reality. And I consider myself an encryption absolutist! But I think the powers arrayed against it are too strong (and in some areas, too morally correct) to fully resist. Which devolves to creating a compromise, and hopefully one better than "Government has no keys, any of the time" or "Government has all keys, all the time."
- pavel_lishin 3y agoSo instead of stealing a single key, the FSB has to steal three?
- ethbr1 3y agoYes. In addition to two of those keys being attributable to the federal government. Which, at least in the US DoD's case, already manages the world's largest PKI system. The key difference with the UK scheme would be (1) the tech company would retain the final decryption key & (2) any use of that decryption key would be required (technically and legally) to generate a public audit record (albeit optionally obfuscated if the court order so requires it).
- EGreg 3y agoThe client side devices / cameras / whatever would send the encrypted copies off-prem, to be decrypted in the case of proper due process and authorization. But it would require interactively querying a distributed database that is managed by agencies or networks representing civilian interests, and these agencies would rate-limit the queryinf and disclose every query, who did it and why. We need more transparency in our governments and security agencies (including FSB, CIA). Start with transparency on why the need certain data. More here: https://community.qbix.com/t/transparency-in-government/234/2 https://community.qbix.com/t/transparency-in-government/234/...