Hacker News new | ask | show | jobs
by devit 3836 days ago
That's not correct.

It's perfectly possible and trivial to put in a backdoor that only works for people who have access to a specific private key.

Obviously if that private key gets stolen anyone can then access the backdoor, but that's true for anything, and you can mitigate it by storing the key in self-destructing immovable hardware with access limitations, as well as periodically changing the keypair (with signed updates).

The real problem is that there is no single "good guy" to entrust with that private key: in particular humans are inherently not fully trustable or good and both individual consumers and other governments have no interest in using or allowing backdoored products.