Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Can you link it? The relevant law written in a really stupid manner, it requires to give keys for decrypting communications, which in case of TLS means session keys. Of course no sane company would log them, so they have nothing to give in the first place. But refusing to share keys speaks nothing about sharing messages themselves.

One justification for sharing keys could be that security services want to use data recorded by SORM (and nowadays we also have the goddamn Yarovaya law) as an evidence and to do that you have decrypt it. Luckily for us modern security frameworks are built around ephemeral keys and forward secrecy.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: