4 ms·
I'm sorry if I wasn't clear. I wasn't meaning to limit my argument to data in transit - I was also including data at rest. To answer your question though, end
by csandreasen 12y ago
I'm sorry if I wasn't clear. I wasn't meaning to limit my argument to data in transit - I was also including data at rest.
To answer your question though, end-to-end encryption of data in transit will obviously interfere with an employer's ability to log transactions.
I think Mr. Baker's arguments were more directed at the recent ubiquitous iPhone encryption controversy (in fact, after doing a quick search, he made almost the exact same argument in the NY Times directed explicitly towards Apple[1], although I think his wording could be toned down slightly). Since the decryption mechanism on the iPhone is tied to chip inside it, it limits a company's ability to hand you a corporate iPhone and still be able to monitor what you're doing with it, hand it over to the cops, etc.
Baker makes the further argument that while Apple can encrypt everyone's data to the chagrin of the FBI and the federal government is unlikely to enact any laws preventing it or hindering sales, Apple will have a much harder time doing the same in certain foreign markets. A country like China will likely have much more political will to push Apple out of the market if their cops can't decrypt people's phones. Maybe that will ultimately be a good thing, but by trying to send a message to the US government they might be opening up a much larger can of worms overseas.
[1] http://www.nytimes.com/roomfordebate/2014/09/30/apple-vs-the-law/data-access-shouldnt-be-up-to-companies-alone http://www.nytimes.com/roomfordebate/2014/09/30/apple-vs-the...
- logicalman 12y agoApple could just sell backdoored phones in China and encrypted phones in America.
- Zigurd 12y agoUnless that data is at rest somewhere outside an organization's control, that still does not require end to end Enron with key escrow/recovery.
- csandreasen 12y agoI think I misunderstood your initial question - the I (well, really, Stewart Baker) was trying to make was that selling devices which are automatically encrypted with keys that can't be escrowed by the owning company (like the new iPhones) isn't going to be very welcome in a corporate environment. > end to end Enron I think you meant "end to end encryption". I'm guessing you're typing that on iPhone :)
- Zigurd 12y agoThat was Android's auto-incorrect. Evidently Google doesn't think I need end to end encryption either! I understand your point, but key escrow and most corporate use cases don't overlap. You are better off not managing user keys, with or without key escrow, and, instead, securing your links back to your infrastructure with a VPN and encrypting your storage to secure data at rest. Key escrow gives you no more protection, or access. It's just more complicated. Key escrow, therefore, is only useful for spying on individuals' interpersonal communication, and Baker knows this very well.