4 ms·
Encrypted backups are an intractable technical problem. The key is on the device you’ve lost, so another copy of the key must be saved somewhere. There has to
by jacksnipe 2y ago
Encrypted backups are an intractable technical problem. The key is on the device you’ve lost, so another copy of the key must be saved somewhere.
There has to be an element of trust, or else the actual use case that 99.9% of users have — I lost my device and want to restore my <whatever> - can’t be met.
It’s not like there’s some great alternative solution they’re intentionally neglecting.
- like_any_other 2y ago> another copy of the key must be saved somewhere Like a password you memorize? Or write down on a piece of paper and store it somewhere safe?
- gruez 2y agoBoth will inevitably get lost/forgotten, especially if it's a password that isn't used on a regular basis. Even for regular backups users rarely test recovery protocols. They just turn it on and call it a day. Heck, sometimes even companies don't even bother doing it, and find out that their disaster recovery protocols aren't up to snuff after they've been ransomwared.
- like_any_other 2y agoThere's nothing inevitable about it. If a user would rather risk forgetting/losing a password, than governments covertly and cheaply spying on them, they can do that, and the problem is perfectly tractable. It's only intractable under the demented requirements of delegating all security to someone else, and at the same time expecting to be secure against the entity you have delegated all security to.