← Back to context

Comment by Xss3

2 days ago

What if the 'secret' is your passport/id/tax records? Id like them to keep those secret for more than 20 years.

The common answer here is that they should destroy them instead.

  • Yes but if they're ever sent over an HTTPS connection that was established using ECDHE key exchange, anyone who recorded that can make it public in the future if quantum computers exist.

    On the other hand - we already give our passport information to every single airline and hotel we use. There must be hundreds if not thousands of random entities across the globe that already have mine. As long as certain key information is rotated occasionally (e.g. by making passports expire), maybe it doesn't really matter