Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Then perhaps I suggest you search Microsoft Skype. Providers can be forced to modify code as well:

https://www.google.com/search?q=microsoft+skype+legal+interc...

Do you seriously doubt Microsoft was forced to include legal intercept in Skype after reading the first 3-5 links there ?

So I disagree with your assessment that it provides any protection whatsoever. Perhaps it raises the difficulty a bit.



It is a perfectly sensible threat model to exclude government intervention. Perhaps more sensible, on the grounds that the government can always make your life hard in other ways, and the government can get away with not following the law. There are lots of meaningful attackers who are unaffiliated with the government, and it's absolutely worth protecting against them.


This does not result in a change of threat model at all. That's what I've been pointing out. It does not protect against anyone at all, nor does it make you more vulnerable to them.

It does not exclude government intervention at all. The government still has the power to compel a change in the code that works with the encryption keys. When that happens, exclusive access to the keys, to put it mildly, won't matter.

If you think differently, let's see you put your actual trust in this process. You keep access to all your encryption keys and passwords, I even promise not to copy them, but you log into your web banking using a web browser I control. Which is the equivalent of the situation discussed here: I control the code interpreting the encryption keys, you control the encryption keys. Depending on your bank's authentication method I may or may not be able to copy the keys, but either way I'll be able to, say, change a bank transfer you make to my liking, which is really the point anyway. So I will transfer a suitable fee for your education, let's say $100, "without access to" your encryption keys to some charity of my choosing. Deal ?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: