Are there any real-world examples where encryption backdoors have been successfully used without compromising cybersecurity? How do different governments and tech companies approach this issue, and what are the implications for global digital security?

  • DomeGuy@lemmy.world
    link
    fedilink
    English
    arrow-up
    29
    ·
    12 hours ago

    Are there any real-world examples where encryption backdoors have been successfully used without compromising cybersecurity?

    No. Adding a backdoor to cybersecurity is fundamentally introducing a vulnerability that can be exploited by an attacker.

    A backdoor in your IT security is like a hidden button to bypass the lock on the impenetrable front door of your impenetrable house. Sure, it makes the police serving a warrant easier, but now there’s a button that anyone can push to bypass your door.

    What you will find are instances with no apparent violations. Just like setting all the nuclear weapons to have the exact same easily remembered activation code didn’t actually lead to a nuclear exchange.

    • WhatAmLemmy@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      3 hours ago

      What you *will* find are instances with no apparent violations. Just like setting all the nuclear weapons to have the exact same easily remembered activation code didn’t actually lead to a nuclear exchange.

      This isn’t a great example. Not even a backdoor. That’s an example of weak security, at the final stage behind multiple layers of extremely strong security. If an adversary had got to the point where they were at an ICBM bunker console, and the only thing stopping them was a 4 digit code, it was already basically game over.

      The backdoors our corporate oligarchs want have zero safeguards, and once discovered grant any attacker the keys to the entire kingdom, remotely. It’s more like the only security being the 4 digit code. It fundamentally weakens the security of everyone, and every system we rely on, to the extent any attempt to do it should be considered a direct act of war against us — as treasonous sabotage, that only our worst enemies would attempt.

      • DomeGuy@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        17 minutes ago

        I see you understood the point made by the example.

        For nuclear weapons specifically, the activation code was supposed to be a command and control measure to prevent unauthorized use. Having it both be an easily remembered code and one widely known made that whole system meaningless theatre.