back

by chha·8y ago·view on hn ↗
"We know from experience that the largest companies have the resources to do what is necessary to promote cybersecurity while protecting public safety. A major hardware provider, for example, reportedly maintains private keys that it can use to sign software updates for each of its devices. That would present a huge potential security problem, if those keys were to leak. But they do not leak, because the company knows how to protect what is important." (Quote from Rod Rosenstein in the article).

This kind of says it all, doesn't it? It's not a matter of if the keys from these large companies are exposed, just a matter of when, similar to what happened to Piriform earlier this year. If all such companies are to keep master keys which can decrypt communication going through their software they are likely to be an even bigger target.

According to Amnesty 119 out of 160 governments had restrictions on freedom of expression in 2014. I can think of several that are likely to be interested in being able to read whatever messages are being sent in order to target dissidents. Journalists are in many cases depending on privacy and security to be able to do their job. At the moment the US is ranked at 43 out of 180 for freedom of the press by Reporters without Borders; if Rosenstein gets his wish, what is the likelyhood that journalists will be among the first to be targeted?

There can be no middle road or "responsible encryption" as they describe it. The data is either encrypted with the recipient being the only one with the means to decrypt it, or it's not encrypted at all.