Hacker News new | ask | show | jobs
by chadillac83 3838 days ago
Putting even the most secure and resilient backdoor should be considered a failure of freedom, privacy, and politics.

At the end of the day backdooring encryption does nothing but weaken everyone's security without actually helping intelligence agencies, at least in the face of serious actors.

Fine, agree to a global backdoor or all crypto with a handful of trusted key holders, how long until the algo or key is leaked, how long until a flaw in it's implementation is found, how long until some TSA agent is photographed with the password blinking on his screen in a news article.

All this will do for bad actors is ensure they assume whatever service provider isn't to be trusted in their implementation and just use a 3rd party process and/or open source tool chain to produce encrypted messages that will be routed over already encrypted networks. Great, your backdoor got you to a second layer of ciphertext that you still can't make heads or tails of, meanwhile you've weakened the security of literally every person on earth.

A backdoor is unacceptable, no matter it's perceived strength, value, or safety.

2 comments

Encryption with a backdoor is not weak it's unencrypted. Anyone who says they want such a thing should surrender their band account credentials first so we can demo what will happen.
I understand the aversion to backdoors and am quite sympathetic to the view that all encrypted communication should be revealed only to the sender's intended recipient(s). However, the choice is not always ours to make.
How do you propose to remove that choice from me?