Well, we must first define who ‘real people’ are. I assume they are people who not are experts, nor involved in the privacy debate. Actually ‘real people’ also don’t actually understand how the Internet works, but they don’t want to be hacked and all their emails read.
This argument is like saying that ‘car drivers are not interested in seat belts or crumple zones in a car…’ until they have a crash. When ‘real people’ are told that their credit card details will be released to cyber criminals if they don’t use HTTPS, most ‘real people’ would say that they would want to use encryption to protect their details. If they were told that someone could ‘sniff’ the password to their email account, most ‘real people’ will want to use encryption… and so on.
The debate in the UK around backdoors in cryptography has possibly hit a new low, and can’t really go much lower.
Why do we need any security at all, and should the UK ban any form of cryptography, and you can’t pick-off end-to-end encryption and not ban HTTPS (which is nearly end-to-end)?
She proposes that the government should read every single message from a UK citizen, in order to protect society, but says:
The government supports the use of strong encryption and does not want to ban end-to-end encryption
I’m struggling how we bridge the gap, as HTTPS does a pretty good job on securing the connection and isn’t end-to-end encryption. I wish I had a magic wand and NOBUS or Escrow!
…and in many cases it just isn’t possible to capture the encryption key (as the encryption key is not stored on any servers and generated only on the hosts)
To break HTTPS, will social media sites hand-over private keys to government agencies? Think about how much those keys will be worth to a foreign state, and the damage that would be caused it they were leaked!





