Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What are you talking about. You think service providers can backdoor aes-gcm? There will always be technology that they cannot get around. The only way to backdoor is to explicitly change the encryption.


Are you misunderstanding on purpose?

This is not specific to 'backdooring aes-gcm implementations' at all. Read again what I wrote, namely this is the general status quo on 'information system security': they don't need your password or aes-gcm key to watch if they really want to. You would be a fool to presume anything else.


Service providers like say Apple and Google can push an update to your phone which will intercept all that data after it has been decrypted.


I understand. So don't use them. There are plenty of OS alternatives




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: