Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> I don't see why, hypothetically, they can't all be sent with encryption that the government has a secret key to decrypt.

Because it's too risky, simple as that.

Let's say there is a single, super-secret-key, for government use only, that can decrypt any encrypted message on the planet.

What happens if this key is leaked? What if it's found out? What if the implementation of that key turns out to be buggy and is cracked? Remember, once there is such a key, it won't just be some criminals in godknowswherecountry trying to get it, it will be state-level actors with unlimited funds, resources and manpower.

If a single one of them gets their hands on this key, even ONCE, it's game over. Our modern society relies on encryption. If this key gets out, the results could be catastrophic; eg. Airplane navigational data manipulated in flight, stock market data manipulated in transit, financial transfers wide open for everyone to read and manipulate at will, control data for electrical grids, hydroelectric dams, nuclear power plants out in the open...it would be anarchy.



I feel there is already a similar problem with the internet in general -- there exist keys which could be used to sign a HTTPS certificate for any website. If you work your way up the heirachy there are some very high-value keys, and the same kind of problems you describe would occur. However, we all just seem to live with that.

Something similar could be set up with, with a collection of keys. I'm not saying it's a good idea, but we already base the security of the internet on a small number of top-level encryption keys.


Difference 1: These certificates are used for the purpose of Authentication, not Encryption. If they get compromised, bad actors can impersonate certain entities for some time, but they cannot decrypt any prior recorded traffic to these entities.

Difference 2: If something happens to these keys, the CA can simply revoke the validity of the public key. This is a major pain in the _ for everyone involved, especially since all downstream certs needs to be re-issued and signed, but it's manageable. A built-in key that is somehow algorithmically included in every encryption mechanism, cannot easily be changed when it's leaked.

Difference 3: There is no single "highest Certificate Authority", so there is no single key to compromise the whole system.

Difference 4: These keys are ordinary asymmetric keys. They are not built-in backdoors into the system.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: