4 ms·
Use OpenPGP software on your local device (GnuPG). Never copy your private key into the could. Set a super strong password on the private key. You now can have
by 16s 13y ago
Use OpenPGP software on your local device (GnuPG). Never copy your private key into the could. Set a super strong password on the private key. You now can have point to point encryption that is "military grade" (per Bruce Schneier) and no one but you has access to the private key.
It's not that hard to do either. Nice point and click convenient web interface or true privacy. Pick one.
- DanBC 13y agoGo to prison (US: Contempt of court? UK: RIPA) unless you hand over your key.
- jacalata 13y agoyes, but at least you get to make that choice for yourself, rather than having somebody else get to decide 'go to prison or hand over DanBC's key?'
- joering2 13y agoI was wondering, what if you are trying the key and it doesnt work... you forgot it for example. You just really cannot open it yourself! Would that be contempt of court?? How do you convince the judge...
- mpyne 13y agoIn the U.S. I believe at least one court circuit has ruled that you cannot be compelled to give up an encryption key if doing so would involve self-incrimination [1]. The 'catch' is that if the government already knows generically what incriminating data you have they can order you to produce it (as it's not any further incriminating). Or something like that? Recent decision though, so things can still change. http://yro.slashdot.org/story/13/04/24/1458203/federal-magistrate-rules-that-fifth-amendment-applies-to-encryption-keys http://yro.slashdot.org/story/13/04/24/1458203/federal-magis...
- anon10191 13y agoBut how far could they go? Could they compel GnuPG authors to secretly weaken GPG, along with a gag order? I know that seems like it's taking it to the logical extreme, but if they can compel web service authors to alter their apps to insert exploits (assuming that's what happened), why couldn't they compel open source desktop app authors to do the same? The only difference being that the GPG authors would have to be really sneaky to avoid code review. Possibly with "help" from the NSA.
- computer 13y agoYou should look closer at what this type of orders actually compel a service to do. In the lavabit case, my theory is that it went as follows: - The FBI compels lavabit through a FISA warrant/NSA to produce Snowden's emails/data/etc. - This data is encrypted, so lavabit cannot comply immediately. However, on logging in, Snowden provides lavabit with his password so that they can decrypt the emails. - Since lavabit then has the password and access to the emails, they are now required to hand that over to the government. They may need to add some code to store the password, but that is not a fundamental change to the system; it is merely a way of intercepting the data they are sent and required to hand over to the government. So [I think that] the government does not order lavabit to make changes, it orders it to produce evidence. Such an order would not make much sense when aimed at the GPG authors.