logo Welcome, Guest. Please Login or Register.
2024-05-08 22:24:29 CoV Wiki
Learn more about the Church of Virus
Home Help Search Login Register
News: Do you want to know where you stand?

  Church of Virus BBS
  General
  Science & Technology

  Government to force handover of encryption keys
« previous next »
Pages: [1] Reply Notify of replies Send the topic Print 
   Author  Topic: Government to force handover of encryption keys  (Read 739 times)
pickler
Archon
**

Posts: 15
Reputation: 8.45
Rate pickler



I'm a spitting llama!

View Profile
Government to force handover of encryption keys
« on: 2006-05-19 04:51:55 »
Reply with quote

Some more pointless modifications to the Law. Or are they pointless?

Source article: http://news.zdnet.co.uk/0,39020330,39269746,00.htm
Source: ZD Net UK
Authors: Tom Espiner
Dated: 2006-05-18

Businesses and individuals may soon have to release their encryption keys to the police or face imprisonment, when Part 3 of the RIP Act comes into effect

The UK Government is preparing to give the police the authority to force organisations and individuals to disclose encryption keys, a move which has outraged some security and civil rights experts.

The powers are contained within Part 3 of the Regulation of Investigatory Powers Act (RIPA). RIPA was introduced in 2000, but the government has held back from bringing Part 3 into effect. Now, more than five years after the original act was passed, the Home Office is seeking to exercise the powers within Part Three of RIPA.

Some security experts are concerned that the plan could criminalise innocent people and drive businesses out of the UK. But the Home Office, which has just launched a consultation process, says the powers contained in Part 3 are needed to combat an increased use of encryption by criminals, paedophiles, and terrorists.

"The use of encryption is... proliferating," Liam Byrne, Home Office minister of state told Parliament last week. "Encryption products are more widely available and are integrated as security features in standard operating systems, so the Government has concluded that it is now right to implement the provisions of Part 3 of RIPA... which is not presently in force."

Part 3 of RIPA gives the police powers to order the disclosure of encryption keys, or force suspects to decrypt encrypted data.

Anyone who refuses to hand over a key to the police would face up to two years' imprisonment. Under current anti-terrorism legislation, terrorist suspects now face up to five years for withholding keys.

If Part 3 is passed, financial institutions could be compelled to give up the encryption keys they use for banking transactions, experts have warned.

"The controversy here [lies in] seizing keys, not in forcing people to decrypt. The power to seize encryption keys is spooking big business," Cambridge University security expert Richard Clayton told ZDNet UK on Wednesday.

"The notion that international bankers would be wary of bringing master keys into UK if they could be seized as part of legitimate police operations, or by a corrupt chief constable, has quite a lot of traction," Clayton added. "With the appropriate paperwork, keys can be seized. If you're an international banker you'll plonk your headquarters in Zurich."
Opponents of the RIP Act have argued that the police could struggle to enforce Part 3, as people can argue that they don't possess the key to unlock encrypted data in their possession.

"It is, as ever, almost impossible to prove 'beyond a reasonable doubt' that some random-looking data is in fact ciphertext, and then prove that the accused actually has the key for it, and that he has refused a proper order to divulge it," pointed out encryption expert Peter Fairbrother on ukcrypto, a public email discussion list.

Clayton backed up this point. "The police can say 'We think he's a terrorist' or 'We think he's trading in kiddie porn', and the suspect can say, 'No, they're love letters, sorry, I've lost the key'. How much evidence do you need [to convict]? If you can't decrypt [the data], then by definition you don't know what it is," said Clayton.

The Home Office on Wednesday told ZDNet UK that it would not reach a decision about whether Part 3 will be amended until the consultation process has been completed.

"We are in consultation, and [are] looking into proposals on amendments to RIPA," said a Home Office spokeswoman. "The Home Office is waiting for the results of the consultation" before making any decisions, she said.

The Home Office said last week that the focus on key disclosure and forced decryption was necessary due to "the threat to public safety posed by terrorist use of encryption technology".

Clayton, on the other hand, argues that terrorist cells do not use master keys in the same way as governments and businesses.

"Terrorist cells use master keys on a one-to-one basis, rather than using them to generate pass keys for a series of communications. With a one-to-one key, you may as well just force the terrorist suspect to decrypt that communication, or use other methods of decryption," said Clayton.

"My suggestion is to turn on all of Part 3, except the part about trying to seize keys. That won't create such a furore in financial circles," he said.
Report to moderator   Logged
Blunderov
Archon
*****

Gender: Male
Posts: 3160
Reputation: 8.89
Rate Blunderov



"We think in generalities, we live in details"

View Profile WWW E-Mail
Re:Government to force handover of encryption keys
« Reply #1 on: 2006-05-19 08:29:05 »
Reply with quote


Quote from: pickler on 2006-05-19 04:51:55   

Some more pointless modifications to the Law. Or are they pointless?

[Blunderov] Well, yes, I think so. Given that there is not something terribly important that we don't know, or that the whole thing is just a PR excercise, it is hard to see how the effort (not to mention the damage done to "freedom") justifies the expected results, if any.

It occurs to me that this futile thrashing may have it's origin in the original misbegotten concept of a "war on terror"; our leaders, it seems to me, have mistaken an entirely flesh and blood enemy, Al Quaeda, for an all-pervading amorphus dread. It is as if they are firing wildly in every possible direction except the one that offers the possibility of actually hitting bin Laden.

At first sight this looks insane. But it may be that, as is wont to happen to liars, our wise ones have discovered that they now have to perpetuate the original deception long past the point where it is convenient to do so.

The oe'r vaulting ambition that led to Iraq was supposed to have evaporated unnoticed in the euphoria and freedom of the petal strewn streets of Bagdad. Didn't happen. So now all the old pretense has to be maintained until, somehow, it does.

Best regards.








Report to moderator   Logged
Pages: [1] Reply Notify of replies Send the topic Print 
Jump to:


Powered by MySQL Powered by PHP Church of Virus BBS | Powered by YaBB SE
© 2001-2002, YaBB SE Dev Team. All Rights Reserved.

Please support the CoV.
Valid HTML 4.01! Valid CSS! RSS feed