> It's either a lawful request from any country or none.
My preference would be to group countries into categories that respect users and their privacy, and those who don't. And then don't pursue selling into countries that don't respect privacy. And no one gets "gold key" or "backdoor access". It is only a legal front door to the data the provider possesses in plaintext. Specifically, data residing SOLELY on the device would NEVER be in said provider's possession in plaintext form, if the user desired that.
But that will never happen. Because, growth markets, amirite? (Sad face)
> Should corporations get to decide what a lawful request is? That's a horrible idea either.
Agreed. Corporations don't get to 2nd-level guess the law (ignoring lobbing in this example). They either get to choose to operate within laws of the territories they do business in, or they don't do business in a said territory. This is my EXACT complaint against Uber, AirBNB, etc.
> FWIW, I am appalled by this constant call to weaken encryption. This is not worthy of any country who deems themselves under the "rule of law". It's even more appalling that they do the dirty work for the countries you listed...
In total agreement. Furthermore it is what is view as extremely easy. Of course the NSA/CSS/CIA/ABC/DEF whatever will always target and crack-open the endpoints. To do a double-duty and attack the crypto itself is just fucking annoying to me due to the collateral damage said efforts bring. They already own the endpoints. Just focus on that. Don't attack the math operations.