3 ms·
You're missing my point completely. These folks very well understand that bad people can steal keys. Stolen keys have been a thing since antiquity. It's not ro
by dataflow 2y ago
You're missing my point completely.
These folks very well understand that bad people can steal keys. Stolen keys have been a thing since antiquity. It's not rocket science they don't understand. Every single key in history has had a risk of theft and this is no exception.
The truth is a lot of them understand this just like you. But unlike you, they are willing to accept this risk. You aren't. That's fine. You have a value disagreement -- you don't think the risk is worth it, and they think it is. Which is why you make arguments about the merits of the issue, instead of attacking the other side on their basic literacy. Just because you disagree on values that doesn't mean the other side is stupid or illiterate about the basics.
This isn't about politeness either, it's actively counterproductive to your own cause: insulting people and showing that you lack a basic understanding of their position is a sure-fire way to make sure they dig their heels in and continue to oppose you regardless of the merits of the situation. i.e. it's a grest strategy for losing in the end.
- whatshisface 2y agoI don't believe that France is actually willing to accept that every opposing intelligence agency will obtain the key...
- dataflow 2y agoMaybe they don't think it's as likely as you think. Or maybe they think the time horizon is long enough that it is worth it. Whatever it is, I assure you they are not too stupid to realize this is a possibility. They just differ on either the degree of the risk, or on the value they get in return. In which case, logic dictates that if you believe the actual risk is higher than they would tolerate, to find a way to convince them of that.
- whatshisface 2y agoThat's a matter of facts rather than values. The "impossible promise" is that a private company can keep a kilobyte of data out of the hands of every spy agency on Earth for any length of time.
- immibis 2y agoWhy does this concern apply to the French intelligence agency but not, say, the code signing certificate for Whatsapp?
- whatshisface 2y agoOn one level it does apply to certificates. On another level, pushing a compromised update to every phone in Europe (to gain access equivalent to having a copy of the backdoor) would be noticed by the publisher, and the binary difference would quickly be found by security researchers.
- AshamedCaptain 2y agoAnd yet the immense majority of the population accept & use messaging platforms operated by "not France" where the operator would be able to obtain everyone's key with a couple clicks. (Yes, this includes Apple's).
- whatshisface 2y agoThat makes sense because it has been brought about as a consequence of consumer preference. It wouldn't make sense for it to have been required by the government.
- AshamedCaptain 2y agoUnfortunately, last time I heard, consumers actually dictate what the government cares about.
- immibis 2y agoI think they think when that happens they'll change it. Or they'll change it on a schedule... "Just use HTTPS" is good enough for every website and web app on the planet (including ones that handle more messages than the entire country of France) but not a state intelligence agency can't keep their TLS keys secret?
- whatshisface 2y ago"Just use HTTPS" sends French messages directly to NSA, insofar as those platforms are concerned. In that case there's not even a copy of any encryption key...
- immibis 2y agoFrance is giving everything they receive to the NSA anyway, so there's not much difference.
- kyralis 2y agoThis is spot on. They're not concerned about their own security. They believe that they will have access to tools that will make them safe, but that "those people" will be deterred, and it is acceptable to give up some basic safety for many to catch "the bad people." And, historically, they weren't necessarily wrong. The problem is more that all of the tradeoffs and probabilities from history have been thrown at the window, because it is now trivially easy to phish the majority of a population and getting a master key gives you access to hundreds of millions of individuals that you can reach from around the globe rather than a couple dozen that you can get to in person from a particular apartment complex. Understanding encryption is not the problem. Understanding scale is the problem.