2 ms·
I think I misunderstood your initial question - the I (well, really, Stewart Baker) was trying to make was that selling devices which are automatically encrypte
by csandreasen 12y ago
I think I misunderstood your initial question - the I (well, really, Stewart Baker) was trying to make was that selling devices which are automatically encrypted with keys that can't be escrowed by the owning company (like the new iPhones) isn't going to be very welcome in a corporate environment.
> end to end Enron
I think you meant "end to end encryption". I'm guessing you're typing that on iPhone :)
- Zigurd 12y agoThat was Android's auto-incorrect. Evidently Google doesn't think I need end to end encryption either! I understand your point, but key escrow and most corporate use cases don't overlap. You are better off not managing user keys, with or without key escrow, and, instead, securing your links back to your infrastructure with a VPN and encrypting your storage to secure data at rest. Key escrow gives you no more protection, or access. It's just more complicated. Key escrow, therefore, is only useful for spying on individuals' interpersonal communication, and Baker knows this very well.