Hacker News new | ask | show | jobs
by alfiedotwtf 1463 days ago
> I'm not saying TARs, TANs or TCNs are FUD and you can ignore them

> Apple and Google are free to eliminate it, if they so choose.

Pick one.

Again, a TCN compels a provider to develop a targeted capability, or face jail time.

1 comments

A TCN can only compel a targeted capability where doing so does not require introduction of a systemic weakness.

If the system is secured in such a way that the targeted capability isn't possible (e.g. open-source project with e2e encryption and verifiable builds), the government cannot compel introduction of a systemic weakness (e.g. stop using verifiable builds) to make it possible.

My suggestion is that Apple/Google build their software such that it is systemically secure against targeted attacks.