An Open Letter to President Obama: This Is About Math, Not Politics
medium.com
medium.com
Dillution of the message by polluting it with political nostalgia is annoying. Make your argument that it's pointless from a mathematical standpoint and help spelling it out, not from some guilt-trip by wrongs of the past.
Sure, this increases the risk that the key will be stolen by the bad guys. But that's also a problem with good solutions. On the hyper-paranoid end, there's something like the DNSSEC Root Signing Ceremony[1]. On a more practical note, there's whatever Apple does with their current signing keys. After all, those don't seem to have been stolen and used at large so far.
Of course, this is still a terrible idea, mostly because governments are not often working in individuals' best interests. But it's far from "impossible" to meet the requirements being handed down by US.gov with only a reasonable level of risk.
[1]: https://www.cloudflare.com/dnssec/root-signing-ceremony/
But that's the whole argument. Everyone knowledgable about encryption knows it's not impossible to hand the government a key, they're claiming it's impossible to do so with a reasonable level of risk.
There's no such thing as a "reasonable level of risk" here. If the government has access, every human on the planet has access, so you might as well just give up on encryption entirely because it's doing nothing of value.
For example, here's what happened when we "just give the government a second signing key" to luggage locks http://www.computerworld.com/article/2983558/security/that-t...
It's a pretty extreme position to say that you trust Apple to be able to keep secrets better than the FBI/NSA/CIA
> because it's already happened to luggage
I don't think this is actually relevant. This "vulnerability" being introduced by the TSA is completely irrelevant: wants to get into your luggage they can cut it open if they have to. Luggage locks have always protected against the threat model of "some rando rifling through my stuff" not "dedicated attacker who spends time ahead of time making devices to get into the luggage". The TSA doesn't and shouldn't care about people having copies of TSA luggage keys, it pragmatically doesn't change anything.