3 ms·
I think this is missing one important issue: what if your encryption is highly reliable but the cypher test is hosted in a jurisdiction that has laws requiring
by mcherm 1y ago
I think this is missing one important issue: what if your encryption is highly reliable but the cypher test is hosted in a jurisdiction that has laws requiring the disclosure of the plaintext (perhaps with a court order or a "National Security Letter") and the ability to compel the system owners to obey.
- some_furry 1y ago> what if your encryption is highly reliable but the cypher test is hosted in a jurisdiction that has laws requiring the disclosure of the plaintext (perhaps with a court order or a "National Security Letter") and the ability to compel the system owners to obey. This is a contradiction. If you have such a capability, then your encryption isn't sufficiently reliable. If it is sufficiently reliable, then this law cannot take effect. If, for example, Australia wanted to compel me to backdoor something for their investigative purposes, there's nothing they can do. I live in America. If I hosted ciphertext in Australia, the most they can hope is to terminate the service in their country. This is an availability concern, but the failure mode isn't "the government sees your nudes". > (perhaps with a court order or a "National Security Letter") National Security Letters don't do what you think they do. There are widespread misconceptions about their allowed scope, but they only allow the government to request "subscriber information" from a service provider. That doesn't include "we compel you to backdoor your app, and here's an automatic gag order". If they try to use non-NSL measures to accomplish this compulsion, talk to a lawyer not a cryptographer.
- adrian_b 1y agoThe previous poster has not referred to a backdoor, but to the fact that in certain places, including USA, law enforcement can request from you the decryption key, and if you do not comply they can throw you in jail for an indefinite time, until you comply. In my opinion, as someone who has been born and raised in a country occupied by external invaders, who had installed there a fake communist "democracy" and fake justice, the most fundamental human right is the right to refuse to answer to a question, regardless who asks the question. If in a country such a refuse is sufficient for severe punishments, without the need of any other proof that the one refusing to answer has done anything wrong, then, regardless if such a refuse to answer is labeled "obstruction of justice", "contempt of court" or whatever, in that country any claims that human rights were respected are false. It is a shame for the United Nations that this most important human right is not included in their declaration. In order to be able to oppose an abusive government, the right to refuse to answer a question is much more important than the right to possess weapons (which will always be inferior to those of law enforcement and military, so they are not a solution).
- some_furry 1y agoThe blog post makes it clear that, if the service operator ever even has access to the secret keys to surrender it in the first place, it doesn't qualify as "properly implemented cryptography". See: The Mud Puddle test. The only way they would be able to acquire the key would be to push a backdoored update to the app. Reproducible builds (which implies open source to be meaningful) and binary transparency make that incompatible with gag orders, by design.