3 ms·
> And I know about the Shadow Brokers. Not personal information. "Tools and methods" are in fact considered more sensitive than any personal information in the
by giaour 3y ago
> And I know about the Shadow Brokers. Not personal information.
"Tools and methods" are in fact considered more sensitive than any personal information in the IC. The system you're proposing presumes the existence of at least one unhackable organization, and I regret to inform you that there is no such thing.
- nvm0n2 3y agoI think this sub-thread is getting a bit confused. Firstly, nothing I've proposed demands unhackable organizations. That appears to be a requirement you invented. No security system presumes that! The so-called E2E encryption systems are hackable via several different organizations today: you could hack Meta client teams and insert code into the next releases, you could hack Google/Apple and tamper with the code as it gets shipped via the store, you could hack a phone OEM and insert a backdoor into the devices themselves. Secondly, if you think government agencies would get hacked more often than tech firms then you may be right, but that's also irrelevant to any points being made here. The goal here isn't to design a perfect system, it's just to point out that the claim that no system can exist at all isn't true. Responding to that with "but your comment doesn't contain a full design doc for a system I personally judge as perfect" isn't going to get us far. Governments don't care if the system is perfect, right? They're OK with some leaks from hacked police departments. Thirdly, I haven't even been making concrete proposals! Just pointing out how cryptography works as examples. If I was hired to implement these requirements tomorrow I wouldn't do things directly in those ways, they're oversimplified, hence the references to textbooks. Finally, the point about mass leaks was about "every other form of electronic communication" so responding with a staff database that was stolen by China and never leaked onto the internet isn't a great counter-example (not a leak from a police department, not private citizen communications). Police investigations are targeted anyway, so there's not much to leak. NSA isn't targeted but they apparently can keep their metadata databases secure enough, even if they've sometimes lost control of PowerPoints or malware caught in the wild.