4 ms·
While this is sound advice there is the problem that if you get very big/popular the government can knock at your door with sealed court orders to enable things
by richtr 13y ago
While this is sound advice there is the problem that if you get very big/popular the government can knock at your door with sealed court orders to enable things like wiretapping.
Case in point: "Microsoft’s tweaks to Skype could facilitate wiretapping" http://www.extremetech.com/computing/132935-microsoft-tweaking-skype-to-facilitate-wiretapping http://www.extremetech.com/computing/132935-microsoft-tweaki...
If that has happened or not under the current system we will never know - which is the exact issue the OP was citing.
- tlrobinson 13y agoBuild open-source, encrypted, p2p networks. Fortunately the 1st Amendment is still mostly respected, at least relative to some of the others. [Edit] Now, monetizing such software is an interesting problem. Ripple/OpenCoin may have found one model: include a cryptocurrency that's used as credits in the system, and claim a large portion for yourself, which you can later sell. The problem is if they open source the software too early someone could easily create a new network with the currency allocated to themselves. [Edit] Perhaps that could be solved with a new open source license that forbids forking the network.
- anemitz 13y agoI've also been considering the possibilities of an OSS security focused business. Random thoughts: * Build infrastructure necessary for other developers to build provably secure products on, license this. * Free consumer versions, paid/managed versions for corporations and governments. * Things like secure telephony have business models built in where you could charge per minute (or message) (and probably still be less than incumbent carrier minutes).
- einhverfr 13y agoIf you get there and want someone to bounce ideas off of or help out, feel free to let me know. (chris at efficito dot com). The one huge problem I see here is that designing a managed version which could guarantee security against a wiretap order would be quite difficult. In essence you would have to push all key management issues to your users, and that leaves you a lot less to actually manage.
- einhverfr 13y agoJust to let you know I am planning on doing a series at my blog on thoughts regarding key management of a secure telephony system. My overall thoughts are to have a very tightly controlled key change policy so that a wiretap is only possible where either a customer's certificate authority's key has been compromised (custoemrs would be expected to run their own CA's) or where new calls were being established between parties that had not called eachother before. An interesting property of the system I am thinking about is that when a wiretap would end the next call to a previously evesdropped target would generate a warning.