4 ms·
> Let's say police had a device which they could plug into your phone, which would send a specially signed message - a digital warrant, containing all the info
by buzer 1y ago
> Let's say police had a device which they could plug into your phone, which would send a specially signed message - a digital warrant, containing all the info a real warrant would - which be permanently be burned into the ROM of your phone, after which the phone would surrender its encryption keys, and the police could dump your unencrypted disk.
And when (not if) that device leaks whoever steals your phone will be able to get access all of the things in there.
- torginus 1y agoI'd imagine such devices would be very tightly controlled, being hard to access for civilians, and lets say limited to 1 such device per 1m people(which would also give you an idea of what sort of frequency this is supposed to be used). The keys for every phone would be stored in a central repo, with a separate key for every phoneX every decryptor(which has its own private key). Meaning you'd need a device and the central repo to access users data. But lets say they manage to build a bootleg version, what would be the criminal gain for them? Reading the data doesn't mean they can impersonate you, as the device wouldn't give you access to private keys used for authentication (lets even say these are deleted), only encryption. The criminals could brick your phone and read your texts. There's only very niche cases when this would be worth it to them, like you're the subject of a highly targeted intelligence gathering op.
- buzer 1y ago> Reading the data doesn't mean they can impersonate you, as the device wouldn't give you access to private keys used for authentication (lets even say these are deleted), only encryption. They would gain access to anything that isn't separately protected. Every application doesn't necessarily store their authentication in that separate storage that gets wiped and if there is such a storage, there isn't really anything prevents applications from using that storage for other purposes, for example storing the encryption key for application's data. Gaining access to files, photos, email and such could be used for, for example, blackmail or identity theft. If politicians, police, intelligence agencies and military are not ready to entrust their data behind the same "escrow" mechanism then clearly they don't trust it enough. If it was as perfectly protected from abuse as claimed then they would have no reason to not trust it as well.