Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The blog post makes it clear that, if the service operator ever even has access to the secret keys to surrender it in the first place, it doesn't qualify as "properly implemented cryptography". See: The Mud Puddle test.

The only way they would be able to acquire the key would be to push a backdoored update to the app. Reproducible builds (which implies open source to be meaningful) and binary transparency make that incompatible with gag orders, by design.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: