Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

One of my favorite comics about cryptography. https://xkcd.com/538/

Government routinely posits a desperate need for backdoors in crypto and crypto secured products, but almost universally they get the data they want without needing a manufacturer provided backdoor. So why they insist on continuing to do that is beyond me. It's almost security theater.

If they really want your protected information they will be able to get it. Either through a wrench or a legal wrench. In lieu of that they can use practically unlimited resources at their disposal from who they employ (or contract out to) to the long axis to which most secured devices succumb from, time.

My personal threat model isn't to defeat the government. They will get the data eventually. My personal threat model is corporations that want to know literally everything about me and bad faith private actors (scammers, cybercrime and thieves) that do too.

Ultimately it will take strict legislation and compliance measurement along with penalties to protect the government from overstepping the bounds they promise not to step over already, let alone new ones. It will take even stricter legislation to stop corporations from doing it. There are significant financial and political incentives for our ruling bodies to not do that, unfortunately.

I mean honestly, when you have this kind of ability at your disposal...

https://www.npr.org/2021/06/08/1004332551/drug-rings-platfor...



>Ultimately it will take strict legislation and compliance measurement along with penalties to protect the government from overstepping the bounds they promise not to step over already, let alone new ones.

They will find ways to not comply, often blatantly. They have no scruples.


A backdoor, which works anywhere and way better than the wrench option.


They don't need it, which was my point. They have all the tools the need right now to get what they want. Why should anyone grant them more?


The problem with using a wrench is that the person you use it on knows you have their data. Having a backdoor means they can see your stuff without you knowing it's been compromised.


Why would they not try to get a magic back door that makes their lives easier, even if they don’t need it?


They can't break all the kneecaps. They do want all the data.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: