I've seen this proposed as an enormous loophole, since every backdoor is a "systemwide weakness", and the lawmakers just don't understand that fact.
I've seen this proposed as an enormous loophole, since every backdoor is a "systemwide weakness", and the lawmakers just don't understand that fact.
The classic metaphor is that of a castle wall. If you put a gate in it, no matter how well your fortify that gate, it remains a weak point compared to the rest of the wall.
That was right before 1973. The development of public key cryptography in 1973 adds another option. Take the symmetrical key the device uses to encrypt user data and encrypt a copy of that key using a public key of the entity that the back door is for.
The authorized back door user can decrypt that copy using their private key. If the public key system parameters are chosen correctly anyone else trying to get in who does not have a copy of that private key faces a problem at least as hard as brute forcing the underlying device encryption.
That's always worked... /s
>Labor’s amendments would also clarify that a “systemic weakness” is one that “would or may create a material risk that otherwise secure information would or may in the future be accessed, used, manipulated, disclosed or otherwise compromised by an unauthorised third party”. [0]
I'm not sure how this doesn't cover all exploits - there have been a few cases of vulnerabilities discovered by state agencies being leaked/disclosed [1].
[0] https://www.theguardian.com/australia-news/2019/jan/21/home-...
[1] https://www.telegraph.co.uk/technology/2017/05/15/microsoft-...