9 ms·
It is possible to set up end to end encryption where two different keys unlock your data. Your key, and a government key. I assume google does this. 1. encrypt
by scripturial 2y ago
It is possible to set up end to end encryption where two different keys unlock your data. Your key, and a government key. I assume google does this.
1. encrypt data with special key
2. encrypt special key with users key, and
3. encrypt special key with government key
Anyone with the special key can read the data.the user key or the government key can be used to get special key.
This two step process can be done for good or bad purposes. A user can have their key on their device, and a second backup key could be in a usb stick locked in a safe, so if you loose your phone you can get your data back using the second key.
- echoangle 2y agoWould that still count as E2E-encrypted if another party has access? That would still count as lying to me.
- lttlrck 2y agoThat depends on the definition of "end".
- QuarterReptile 2y agoTo say nothing of the definition of "definition", or at least a common understanding. https://m.youtube.com/watch?v=gRelVFm7iJE https://m.youtube.com/watch?v=gRelVFm7iJE
- blitzar 2y agoIt depends on what the meaning of the word 'is' is
- dtpro20 2y agoTo call it lying is just arguing about the meanings of words. This is literally what lawyers are paid to do. The data payload can be called end to end encrypted. You can easily say to the user that "your emails are encrypted from end to end, they are encrypted before it leaves your computer and decrypted on the receivers computer" without talking about how your key server works. Systems that incorporate a method to allow unlocking using multiple keys don't usually advertise the fact that this is happening. People may even be legally obligated to not tell you.
- mirekrusin 2y agoTIL man in the middle = e2e encryption.
- scripturial 2y agoE2E encryption is not the same as MITM. You’re not adding anything useful to the conversation. E2E encryption is not vulnerable to MITM. E2E encryption is vulnerable only to how many keys there are and who has access to them.
- chii 2y agoSO if google still has access in an E2E system, but you didnt know, is it still E2E? What if google told you they also have a key? Does that change the above answer to the question?
- echoangle 2y agoIf someone except the communicating parties has access to the keys, it’s not E2E encrypted anymore though. At least according to this definition: https://en.wikipedia.org/wiki/End-to-end_encryption https://en.wikipedia.org/wiki/End-to-end_encryption
- catlifeonmars 2y ago> To call it lying is just arguing about the meanings of words. Or, as us lowly laypeople call it, lying.
- echoangle 2y agoWell Wikipedia says this about E2E: “End-to-end encryption (E2EE) is a method of implementing a secure communication system where only communicating users can participate. No one else, including the system provider, telecom providers, Internet providers or malicious actors, can access the cryptographic keys needed to read or send messages.” So if you send another set of keys to someone else, it’s obviously not E2E.
- 2y ago
- barsonme 2y agoE2EE means only your intended recipients can access the plaintext. Unless you intend to give the government access to your plaintext, what you described isn’t E2EE.
- hot_gril 2y agoYes, but going by that, most messaging services advertised as "E2EE" are already not E2EE by default. You trust them to give you the correct public keys for peer users, unless you verify your peers in-person. Some like iMessage didn't even have that feature until recently.
- immibis 2y agoSure is - three ends - you, the intended recipient, and the government.
- mu53 2y agoIs that google's definition or your definition? not being rude, but its pretty easy to get tricky about this. Since you are sending the data to google, isn't google an intended recipient? Google has to comply with a variety of laws, and it is likely that they are doing the best they can under the legal constraints. The law just doesn't allow systems like this.
- gtirloni 2y agoWhat's the intended recipient of your message? It's not Google, right? You're discussing encryption in transit vs encryption at rest in this thread.
- mu53 2y agoI agree with you, but these abstract technical systems have enough wiggle room for lawyers and marketers to bend the rules to get what they want
- brookst 2y agoIf Google is employing this “one simple trick”, they will get sued into the ground for securities fraud and false advertising.
- DarkmSparks 2y agoI expect this is what they are all doing tbh, although isnt google open source? should be checkable, if the binaries the distribute match the source... oh... "a special key" afaik is where instead of using 2 large primes for a public key, it uses 1 large prime and the other is a factor of 2 biggish primes, where 1 of the biggish is known, knowing one of the factors lets you factor any public key with a not insignificant but still more compute than most people have access to. UK has also invested in some serious compute that would appear dedicated to exactly this task. basically if you dont have full control over the key generation mechansim and enc/dec mechansim it is relatively trivial for states to backdoor anything they want.
- hilbert42 2y ago"…two different keys…. Your key, and a government key. I assume google does this." With the present state of politics—lack of both government and corporate ethics, deception, availability of much fake news, etc.—there's no guarantee that you could be certain of the accuracy of any information about this no matter what its source or apparent authenticity. I'd thus suggest it'd be foolhardy to assume that total privacy is assured on any of these services. BTW, I don't have need of these E2E services and don't use them, nor would I ever use them intentionally to send encrypted information. That said, occasionally, I'll send a PDF or such to say a relative containing some personal info and to minimize it being skimmed off by all-and-sundry—data brokers, etc. I'll encrypt it, but I always do so on the assumption that government can read it (that's if it's bothered to do so). Only fools ought to think otherwise. Clearly, those in the know who actually require unbreakable encryption use other systems that are able to be better audited. If I were ever in their position, then I'd still be suspicious and only out of sheer necessity/desperation would I send an absolute minimum of information.
- scripturial 2y agoYes. There is no ability to know one way or the other if Google, and similar services retain a secondary way to access decryption key. In light of this the only option is to _assume_ they have the capability. Given the carefully crafted way companies describe their encryption services, it seems more likely than not they have master keys of some sort.
- baranul 2y agoThat would definitely be a safe assumption, that Google can look into anything they own or is on what they own. It's not like they are strong privacy advocates or don't already cooperate with any state apparatus they see as profitable or to their benefit.
- pinoy420 2y ago> I don’t care for encryption or need it > encrypts a pdf sent to tech illiterate family members