Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't follow. Are you saying that BigCorp would demand key escrow? They already deploy custom email solutions today so I don't see the issue.
 help



I am saying you can't keep the keys just on a stick in the employee's pocket since multiple people need to have access to the data.

And if those keys are stored by a company subject to US jurisdiction, we're back to the same problem.


Well yes, if you hand your keys over that is indeed a problem. Of course handing your keys over to the provider rather defeats the purpose of E2EE so hopefully no one is doing that.

Key escrow is the usual solution to an employer needing access to employee materials.


> Key escrow is the usual solution

Yes, and you move the problem to "is the entity/process/whatever handling key escrow under US jurisdiction"?


Yes, obviously, but key (/account/identity/etc) management is typically a much narrower and well defined problem to solve and in many cases it will already have been solved (centralized management of user accounts, employee ID cards that contain physical tokens, and other such things).



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: