that we give a trusted
* neighbor a spare key to our house...and the U.S. will have that key.
The government says in case you lose you own decryption key,
they will be there to save the day with their LE key. (Key Recovery
has a 'Law Enforcement' key, which is a SECOND key to decrypt the
same traffic.)
Without getting into a lot of technical detail, basically,
the LE KEY = Your Key.
So, because they have a separate but equivalent key, they are claiming
to be your emergency backup key, like a key left with a neighbor.
People who have no idea how computer systems work will
think like that sounds like a reasonable thing.
Like a "good faith attempt to balance...".
Now picture it being YOUR business.
You have a cryptographic key that needs to be protected.
The key itself is a big number you can't memorize.
The key itself is protected by a (MD5-like) password to
unlock access to it. That means the password can be as long
a thing as you'd like to type in, not merely a short password.
As long as you can remember it.
This is standard...MIT's Kerberos and Phil Zimmerman's PGP
use a password to unlock the cryptographic key.
So, how do you back up the key without GAK?
In other words, what do all companies do for this situation now?
A situation that applies to all company data whether or not it is encrypted.
A situation that has
-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 9.1.5
vFsLe6TN6ZJdX/HZYaA9XtkziQqSTJRAt1Q4IUpiU/ROjifHWYJVq1BEsKXzJ6Xw
FToijz6Kuy6dVg4FNXae2oD/gZiyVK9wYYQRjpeoDz1bE7KOvpBu6+jlcQxuh0Vf
O4JLP05cnAi5yVcCkyZXhULzCnKHE6lSAK4M5MSPznb0f5K5Xu5xiLHJiJIegtaQ
oixbkzq7YDDXsg0eYXX4KjuHL/5KhY==
=p5Ty
-----END PGP SIGNATURE-----