ToS is like HR: they both exist to protect only the company.
ToS is like HR: they both exist to protect only the company.
What are you going to do about it? Call your senators, who are now in love with Facebook for giving the federal government access to these previously private communications?
As for the real world... nothing. I quite like signal.
This is, of course, not true about HR and yet another thing people just say to sound cool.
HR’s job is to hire people and run your payroll and benefits. If you have a health insurance question are you going to avoid them because they’re going to fire you as soon as you look at them? No.
If you’re a first level manager molesting a distinguished engineer are you totally safe from HR because you’re “the company”? No.
They will sack anyone if they see it necessary to protect the status quo.
But more importantly, HR will create mindless policies to show you how powerful they are. As border force forcing your sneakers of.
To show you how useful they are. It’s very much a matter of misaligned incentives I think. Of course HR has all day to execute their own policies, so they don’t see them as an overt burden.
No, they don't. They only allow you to verify that some entity that possessed some private key made some claim about some set of bits. It tells you absolutely nothing about whether any of those claims are actually true, including whether the possessor of the private key is who they claim to be.
I said encryption. You can do encryption all kinds of ways. In this case, I am talking about encrypting your own data on a client and not allowing a server to see it. This would just require a secret key derived from a password ran through a password hashing algo.
You only need asynchronous crypto when you involve another party, so it would play a role in a trustless architecture, but I am unsure what your point is.
When I say “verify trust” of a system, I am referring to a product making a claim, such as “your data is private and we don’t sell it” — then backing up the claim by building the product in such a way such that it is impossible to sell it. Encryption + open source is just about all the way to proving that claim, and it can be verified that way.
No, you didn't. You said "modern encryption" which is generally understood to mean public-key encryption.
But even so, your claim is still false because you can't trust your encryption software even if it is open source unless you build (and audit!) your entire tool chain yourself (and nowadays you have to roll your own silicon too if you really want to be sure).
Not when it comes to server-based software.
- If you host your own servers you can still verify.
- if you are using well-designed, human-centric software, untrusted servers (read: all servers you do not have control of / cannot audit) would not have any access to private data due to encryption, and clients can be verified to make sure decryption only occurs on the client side
The trouble is, this kind of software is a poison pill to advertising. It will be a long time before it takes over.
Custodial services can always still exist for those among us that are incompetent.
It's pretty difficult to fully scrub yourself of the metadata involved in making a connection to a server. For sure it can be minimized, like Signal does. But this has inherent UX tradeoffs that most people are not willing to make, like requiring you share your phone number to use the service, and not having server-based backup (yet, at least).
It was once difficult for me to communicate with you, me being a stranger to you and you being the same, having never met in person. But here we are.
We are all experts at solving difficult problems & giving access to those solutions to everyone.
"The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated"
meaning, I got the right to secure my sh*t.
I could have been clearer there. I can see why you replied as such.
I don't know if you've noticed, but the Supreme Court routinely flouts long-held interpretations of statute for nakedly ideological reasons. Rights don't mean anything if the government isn't willing to grant them, unfortunately. I would not bet on this court preserving a right to encryption as you describe it.