Hacker News new | ask | show | jobs
by anf 2996 days ago
That's totally irrelevant to the point that two-user encryption is fundamentally insecure, made insistently by even those who should really know better: https://www.schneier.com/blog/archives/2015/09/tsa_master_ke...
2 comments

The claim made by that article isn't nearly as strong as what you're saying it claims. Two-user encryption obviously can be made secure.

But when one of the keys that can decrypt something is shared by every message using that protocol, it is fragile - a leak breaks everything using that protocol. This is what that article actually says, and seems to also be correct.

A related point is that two-user encryption is insecure when one of the parties has no stake in the contents staying private, which is the case when the government can decrypt your data.

Two-user encryption obviously can be made secure.

I think we're done here.

Your splitting of the hair on "secure but fragile" depends on the assertion that the US government has no interest in maintaining the security of conversations of all US devices? That's inane and insane, respectively.

It is fundamentally insecure, as that article establishes.

Do you have an argument to the contrary?

If it is "fundamentally" insecure, why do Google and Apple and Microsoft and all the other tech companies use it on their employee laptops?