this post was submitted on 28 Nov 2023
766 points (100.0% liked)

196

16484 readers
1926 users here now

Be sure to follow the rule before you head out.

Rule: You must post before you leave.

^other^ ^rules^

founded 1 year ago
MODERATORS
766
encrulepted (retr0.id)
submitted 11 months ago* (last edited 11 months ago) by masimatutu@nerdica.net to c/196@lemmy.blahaj.zone
 

retr0.id/media/bd23a2fb-c7a6-4…

alt text:

Goose chase meme. In the first frame, the goose asks "all the data is encrypted?" In the second, the goose chases a person, asking "encrypted how and with whose keys, motherfucker?"

@196

you are viewing a single comment's thread
view the rest of the comments
[–] pohart@programming.dev 99 points 11 months ago (3 children)

I once had to work with a government agency that insisted they generate and provide my private key.

[–] peopleproblems@lemmy.world 41 points 11 months ago

At least they told you about the wire tap?

[–] 8ace40@programming.dev 28 points 11 months ago (2 children)

I'm migrating millons of encrypted credit cards from one platform to another (it's all in the same company, but different teams, different infra, etc).

I'm the one responsible for decrypting each card, preparing the data in a CSV, and encrypting that CSV for transit. Other guy is responsible for decrypting it, and loading it into the importer tool. The guy's technical lead wanted me to generate the pair of keys and send him the private key, since that way I didn't have to wait for the guy and "besides, it's all in the same company, we're like a family here".

Of course I didn't generate the key pair and told them that I didn't want to ever have access to the private key, but wow. That made me lose a lot of respect for that tech lead.

[–] IDontHavePantsOn@lemm.ee 15 points 11 months ago

So you wanna be key buddies? Respectfully.

[–] uis@lemmy.world 2 points 11 months ago

I know one municipal agency that does the same...