[ Trimming recipients list ] On 27/09/2019 18:23, Linus Torvalds wrote: > It's not the crypto engine that is part of the untrusted hardware. > It's the box itself, and the manufacturer, and you having to trust > that the manufacturer didn't set up some magic knocking sequence to > disable the encryption. > > Maybe the company that makes them is trying to do a good job. But > maybe they are based in a country that has laws that require > backdoors. > > Say, France. There's a long long history of that kind of thing. > > It's all to "fight terrorism", but hey, a little industrial espionage > is good too, isn't it? So let's just disable GSM encryption based on > geographic locale and local regulation, shall we. > > Yeah, yeah, GSM encryption wasn't all that strong to begin with, but > it was apparently strong enough that France didn't want it. Two statements above have raised at least one of my eyebrows. 1) France has laws that require backdoors. 2) France did not want GSM encryption. The following article claims that it was the British who demanded that A5/1 be weakened (not the algorithm, just the key size; which is what the USgov did in the 90s). https://www.aftenposten.no/verden/i/Olkl/Sources-We-were-pressured-to-weaken-the-mobile-security-in-the-80s Additional references for myself https://lwn.net/Articles/368861/ https://en.wikipedia.org/wiki/Export_of_cryptography_from_the_United_States https://gsmmap.org/assets/pdfs/gsmmap.org-country_report-France-2017-06.pdf https://gsmmap.org/assets/pdfs/gsmmap.org-country_report-France-2018-06.pdf https://gsmmap.org/assets/pdfs/gsmmap.org-country_report-France-2019-08.pdf As for your first claim, can you provide more information, so that I could locate the law(s) in question? (Year the law was discussed, for example.) I've seen a few propositions ("projet de loi") but none(?) have made it into actual law, as far as I'm aware. https://www.nextinpact.com/news/98039-loi-numerique-nkm-veut-backdoor-dans-chaque-materiel.htm https://www.nextinpact.com/news/107546-lamendement-anti-huawei-porte-pour-backdoors-renseignement-francais.htm Regards.