Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The problem with these slippery slope arguments is that they start treating unlocking a phone as the equivalent to breaking network encryption when technically they're not at all the same. Apparently the FBI wants you to think they're the same too? If so, don't let them away with it.

Signing a software update with a private key you already have is using crypto as it was intended. We presume private keys can be kept secure with enough effort, or public key encryption doesn't work, https doesn't work, software updates don't work, game over. Any attempts to get private parties to turn over their private keys should be strongly resisted, but requiring them to sign something given a search warrant adds a procedural step that acts as a check on government power (they can verify that the search warrant is valid, minimize scope of the change, and fight it in court if necessary).

Key escrow is a whole different thing, where they require a whole new system to be designed to preserve keys that would normally be destroyed. It's hard to preserve information when the user wants to destroy it (they can block network traffic and destroy the phone), resulting in all sorts of bad effects on system design and new vulnerabilities.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: