- cross-posted to:
- [email protected]
- cross-posted to:
- [email protected]
Services will simply have to stop storing messages, encrypted or otherwise.
I understand the inherit issues/limitations with PGP, but this would be a non-issue if services just stored messages encrypted on disk internal to prevent leaks in case of a breach, but were otherwise unencrypted, and everyone just sent messages like:
-----BEGIN PGP MESSAGE-----\nVersion: GnuPG v2.2.0\nhQEMA+gAAKCRBKxZ12345678EBAAIAAAQABAoAB+P/234567890-=+QWErT\n... (a long string of seemingly random characters) ...\n=sdfsdf\n-----END PGP MESSAGE-----
A lot of the issues with PGP would go away if applications had first party support for encryption and decryption with personally managed keys. You’d still have the issues that come along with personally managed keys though, but if the alternative is every government can compel central services to hand over managed keys, I’m fine with yelling “skill issue” at people who permanently lose access to all their messages.
Looks like the UK government isn’t the only one slobbering at thought of being able to invade people’s privacy
Pas bien
Pas bieeeeennnn