Hacker News new | ask | show | jobs
by benmmurphy 425 days ago
the closest you can get to what you want is a trusted third party who would help derive the final key. so the key could not be revealed to law enforcement without cooperation of the trusted third party who would verify policies like time, etc. it may also be possible to have the 'trusted third party' be a piece of tamper proof hardware. i think generally people are suspicious of these schemes because it relies on 'trust'.

also, i think apple has a scheme similar to this for protecting the passcode from being brute forced when recovering from iCloud backup. however, if this scheme breaks it doesn't reveal the encryption key i believe it just allows the passcode that protects the encryption key to be brute forced which I guess may or may not result in the encryption key being revealed.