logoalt Hacker News

nottorpyesterday at 8:24 AM1 replyview on HN

I am saying you can't keep the keys just on a stick in the employee's pocket since multiple people need to have access to the data.

And if those keys are stored by a company subject to US jurisdiction, we're back to the same problem.


Replies

fc417fc802yesterday at 11:20 AM

Well yes, if you hand your keys over that is indeed a problem. Of course handing your keys over to the provider rather defeats the purpose of E2EE so hopefully no one is doing that.

Key escrow is the usual solution to an employer needing access to employee materials.

show 1 reply