Will there be no end to govt attempts to break encryption? Hand over your data or the kiddies get it, threaten Five Eyes spies
- Reference: 1603103408
- News link: https://www.theregister.co.uk/2020/10/19/e2e_break_five_eyes/
- Source link:
The declaration is a masterly exercise in security administration doublespeak. It starts with a stirring call to righteousness and the power of proper privacy. Encryption is vital to protecting people's use of data, it says, alongside human rights activists in repressive regimes, journalists researching corruption, and all those good things. Who could disagree?
Not JIANUSCUK, which continues: "Encryption is an existential anchor of trust in the digital world and we do not support counter-productive and dangerous approaches that would materially weaken or limit security systems."
Oh dear. Experts will by now be alerted by the skilful deployment of the weasel modifiers "dangerous" and "counter-productive". How so? To whom? And indeed, we're just 80 words in and JIANUSCUK can't keep a straight face any longer. It drops the H bomb followed by the C word. However. Children.
I don't kid. Really, [2]go and look for yourself.
The rest is an absolutely perfect example of the Great Unicorn Prayer of the security services: oh Lord, grant us this day all the data, but keep it from the sight of the evil-doers. And if that's not possible, because it isn't, even for thou, oh Lord, force industry to give it to us by framing them as complicit in child sex abuse. Amen.
Departing MI5 chief: Break chat app crypto for us, kthxbai [3]READ MORE
As Reg readers will know, we have been here so, so many times before. Early '90s US president Bill Clinton and the [4]Clipper chip kicked things off as the internet got its groove on. This would have been mandated hardware encryption with magic unlocking keys known only to, well, anyone with the right hat. Unfortunately, the encryption-breaking protocol was itself broken. Since then, there has been a constant cycle of government demands for the impossible "safe access" by back doors.
A fun game is to Google the name of any recent Home Secretary and "End-to-End" and see how far back you have to go before “calls for an end to” isn’t in the title of the top result. (Hint: it’s more than a decade.)
What's that? Encryption's OK now? UK politicos Brexit from Whatsapp to Signal [5]READ MORE
You cannot make an encryption system insecure without making it insecure. Nor do you need to. Just this summer, by good old-fashioned police and security work, the [6]French and friends cracked Encrochat wide open - a custom Android system with baked-in end-to-end encryption that was the chatter carrier of choice of the criminal fraternity. Hundreds of arrests followed, and nobody else’s data was at risk. How did les plod pull it off? They hacked the phones, bypassed the encryption and hoovered up the bad guy blether. It took proper court orders, but nothing not in keeping with standard surveillance. And the French, like all the EU, clearly want nothing to do with JIANUSCUKery. Odd that.
It is of course open to any state to break its own laws, or frame them in such a way that it doesn’t need to. Both the UK and the US are brazenly bounding down that path, and [7]Human Rights Watch says of India that “In 2018, the government... harassed and at times prosecuted activists, lawyers, human rights defenders, and journalists for criticizing authorities. Draconian sedition and counterterrorism laws were used to chill free expression.” So that’s almost half of JIANUSCUK behaving in ways that its own declaration says encryption is essential to protect against, at the same time as calling for that encryption to be turned off on demand, Do they think we just take them at their word?
After huffing and puffing for years, US senators unveil law to blow the encryption house down with police backdoors [8]READ MORE
Only those of us with 'nothing to hide' who end up with nothing hidden
And it is only the sort of encryption that ordinary people use that would be broken. The child abusers are already buried deep within multiple layers of encryption; if every wish in this declaration were to come true, that wouldn't change one jot. It is impossible to enforce a human law that breaks the laws of mathematics, and mathematics says that if you want good encryption you can have it, through code that can be written on the back of a postcard.
By focusing on the tech industry to do its dirty work, JIANUSCUK is admitting there is no practical or legal way to back-door all encryption. The bad guys will carry on using the good stuff, it's only those of us with "nothing to hide" who'll end up with nothing hidden.
It is likely that this exercise in futility will end up in the bin like all of the rest, but only because people who know such things for what they are keep calling them out. I don't know when Priti Patel (the [9]latest UK Home Sec to call for an end to encryption ) will leave government - hell, I don’t know how she got there in the first place - but I do know that the next person in that seat will waste no time in calling for an end, endlessly. I'll be there, blowing raspberries. Be there with me. While we can. ®
Get our [10]Tech Resources
[1] https://www.theregister.com/2020/10/11/international_statementon_end_to_end_encryption_and_public_safety/
[2] https://www.justice.gov/opa/pr/international-statement-end-end-encryption-and-public-safety
[3] https://www.theregister.com/2020/02/26/mi5_chief_itv_interview/
[4] https://www.theregister.com/2020/01/27/clipper_lessons_learned/
[5] https://www.theregister.com/2019/12/20/uk_conservatives_brexit_from_whatsapp_to_signal/
[6] https://www.theregister.com/2020/07/02/encrochat_op_venetic_encrypted_phone_arrests/
[7] https://www.hrw.org/world-report/2019/country-chapters/india
[8] https://www.theregister.com/2020/06/24/us_encryption_backdoor/
[9] https://www.theregister.com/2019/07/31/home_sec_priti_patel_five_eyes_encryption_controversy/
[10] https://whitepapers.theregister.com/
so they don't have to pay money to have actual police officers doing proper work
Nope. You're falling into the trap. It's not about stopping crime. It's about stopping thoughtcrime. As pointed out in the article, actual criminals are already using (probably multiple layers of) encryption that won't be affected by this hypothetical backdoor: If JIANUSCUK get what they want, it will have near-zero utility for its (publicly) stated purpose. And they know it. They're lying - the actual purpose is that they want more mass surveillance. Pure and simple. That's pretty much all this would achieve (well, apart from making everyone less secure).
To engage in discussion about how backdooring encryption will help stop crime is to fall into the trap and believe their bullshit framing story. It won't help stop crime. It's not a cheaper, easier alternative to real police work. All it will do is help stop thoughtcrime.
I think you're givng them too much credit,. While there may be a bit of misdirection here, these are the same policitians who routinely make calls for finding out "what we do best and finding more ways of doing less of it better". (W1A). That's even assuming they can remember the policy they've just announced.
Futility
These calls for security and "targeted" surveillance are completely futile as they've been playing this same ol' record for years and years now and the tech companies seem to be ignoring them completely.
If LEA and Intelligence agencies believe it's possible for tech companies to put in a backdoor without compromising security, maybe they can tell us how, in the open and in public. Chances are the proposal simply contains a "secret key" somewhere in the program. But they'll promise to keep it a secret because they're good at that.
Nothing's going to happen, unless governments pass laws to enforce these backdoors, like they've done in Australia. I still haven't seen any evidence that any tech company responded by adding a backdoor. More likely we'll see legal challenges and fines by Australia to force companies like Facebook to tow the line.
Currently, there are huge gaping holes in the security of many end-to-end encrypted products. WhatsApp, for example, removes the encryption if you backup your conversations to Google Drive. And let's face it, there's always someone in your secret chat group which doesn't know this and backs up their conversations to the cloud.
But LEA and intelligence agencies are probably foreseeing that these loopholes will be closed in the near future, shutting them out.
Not 5EYES
Just some dumb politico trying to legitimise their latest sound bite
There is no way the military and intel comunity would want back doors plastered all over the full IT stack of the gear they use
Re: Not 5EYES
> There is no way the military and intel comunity would want back doors
What have the military or the intel community to do with it?
Keep in mind those measures are for the Great Unwashed, not the PtBs: The military can carry arms, the average Joe in the streets can't. This is just an attempt to outlaw yet another item threatening their full control over the masses.
Since saying "Hey bozos, we want in on all your little secrets" might create some resentment, they try the time-tested guilt trip trick: Do you hear the poor little children weeping because of your cruel selfishness? The cute poor innocent little children? You bad, bad person?
I'm confused
it is a new demand, or is it a repeated piece of no-longer-news? I'm pretty sure I saw something along these on the reg a couple of weeks ago only, to the (expected) outrage in the commentard quarters? (to clarify, I was disgusted too, OUTRAGED, no less! ;)
Re: I'm confused
Indeed, see:
https://www.theregister.com/2020/10/11/international_statementon_end_to_end_encryption_and_public_safety/
The usual drivel from the usual bunch of wankers who have no idea how computing works, I suspect.
No idea how cryptography works, either. Don't necessarily need a computer to do the math, but it sure is faster.
(...as long as you don't mind side-channel snooping. Then again, I'm sure anyone truly determined could side-channel the activity of my desktop printing calculator, too. No shielding, that's for sure.)
Dear Security bods
Online "trust", and the concept of encryption, only works if one can feel reasonably certain that the communications between the server and the user is secure, encrypted, and untampered with.
If you want access, this implies that there is an intentional weak link that permits you to see what, cryptographically, you should not be able to see. And if you can see, then not only can others see, but there's the possibility that you or others can modify .
It's at about this point that trust evaporates.
Because, believe me, if it is known that there is a backdoor, then people far smarter than you in countries that you would consider hostile will be pulling apart your entire algorithm bit by bit. And when that weakness is known, the entire security theatre is useless.
Don't take my word for it, Google for "webrip" and "bdrip". All the encryption and protection thrown out by the movie studios has not done a whole lot to stop piracy. Build in a weakness, it will be found.
Re: Dear Security bods
@heyrick
Quote: "Online "trust", and the concept of encryption, only works if one can feel reasonably certain that the communications between the server and the user is secure, encrypted, and untampered with."
While this true, there some other aspects to "trust" -- or lack of it.
1. If the encryption is provided by a service provider (e.g. Signal) then the user is trusting Signal. This need not be the case if the user is using private ciphers BEFORE the message enters the channel. In that case the user has moved the "trust" from the service provider to their own encryption.
2. What the quote fails to recognise is that metadata can still tell a snooper something about what is going on -- even if the DATA ITSELF is encrypted. The NSA and GCHQ and all the other spooks are still able to collect metadata about the account holder, the IP address, the location of the originator of a transaction and a time stamp. If needed, an internet service provider can be persuaded to provide details of the content of transactions which match this metadata. (And that's before we consider matches with widespread camera data.)
*
Someone wanting A VERY HIGH LEVELS OF "TRUST" needs to address BOTH item #1 and item #2. The ONLY way to do this is to ensure that the transactions which a person initiates are:
a) Using private ciphers, and....
b1) Using an anonymous end point (no link between an account and a person e.g. with a burner phone) or....
b2) Using an end point deliberately linked to some other person or organisation (e.g. hijacked WiFi, internet cafe, VPN, etc.)
*
And even if either b1 or b2) is in place, the person needs to take additional precautions:
c) Ensure that their "honest citizen" phone is never active at the same time and place as the burner phone
d) Ensure that transactions are always sent or received out of the view of CCTV
e) Ensure that they do not "give the game away", for example by using a personally identifiable account (say checking email or FB)
*
And if these precautions are not onerous enough, the RECIPIENT(S) of the "trusted" messaging need to be taking exactly the same precautions.
*
Still, from all of the above, it's absolutely certain that with planning, training and care, anyone, any group, can increase their "trust" in their communications WHETHER OR NOT the spooks deploy backdoors!!!!
Realism?
I seem to remember an Australian PM who said something on this topic on the lines of "we don't obey the laws of mathematics here, we obey the laws of Australia".
However there are encryption systems - one time pads, for example - that can defeat any attempts at breaking regardless of any desires on the part of "authorities". Of course there are also codes, that can be entirely impossible to break unless coercion is applied.
Re: Realism?
The one time pad is unbreakable provided you can secure the pad and never reuse it; but you still hit on the key distribution problem of getting the pad to the other user.
Fortunately, GCHQ discovered the solution to that issue back in the 1970s with public key encryption which - oh bugger - kind of gets in the way of authoritarians everywhere.
Re: Realism?
The problem with OTP encryption is that it becomes trivial to construct a OTP that will decode the encrypted message into anything you want. Thus the ptb can first prove that the encrypted message came from you, then produce a OTP that they claim to have recovered or "cracked" which shows the message was a terrorist plot or kiddie-porn etc. You cannot do the same with a message encrypted with PGP, AES or 3DES etc. Only one unique key will result in an intelligible decode.
Re: Realism?
I can just tell the authorities to SOD OFF and I will go completely open source code written in HTML-5 if I have to, or any one of the 20 computer languages/assemblers I know and am quite good at when coding INVARIATE, CODE-BASED or ONE-TIME PAD based anti-quantum computing encryption-breaking algorithms (i.e. Shor's) that works on my custom coded text, audio and video communications software.
Since I store and run ONLY WITHIN the Level-0/Level-1 caches and local registers of the CPU themselves I can PREVENT Ring-0 or even Ring Negative-ONE hypervisor code/BIOS code from seeing/intercepting the keys and plaintext data!
I think I can EASILY MAKE Australia OBEY the rules of MATH!
V
They want more and more access, but they don't seem to have the resources or the skillset to make use of what they have already got.
Won't that be Fatima's job?
Put your money where your mouth is.
Instead of complaining nobody will do it for you commission someone to provide software to do this. It must, of course, stand up to expert infosec inspection to ensure it actually does keep out miscreants, including ensuring that collected data can't get leaked or misused.
When you've cracked that you can go ahead and get it used.
Re: Put your money where your mouth is.
HMG is already spending a reputed £7k PER DAY per 'consultant' for the UK's Covid-19 Test Track and Trace 'world beating' system. We cannot afford yet more wild goose chasing, thanks.
I cannot help feeling that this is basically a test of pubic attitude towards backdoored encryption products, as the various security agencies, GCHQ, NSA etc. will have undoubtedly informed their ministerial bosses that what they claim to want is not technically possible.
I also wonder whether it would apply to the banking sector and businesses using encrypted VPNs for secure communications between sites of company sensitive information. I wonder whether the powers that be asking for this have considered the possible court case where someone is charged with releasing company data that affects share dealing prices, but claims the backdoored encryption was responsible and sues the government.
[1]XKCD as always....
[1] https://xkcd.com/538/
Backdoors solve nothing
OK, so it helps them catch idiots but anyone with a brain or working for a professional spy agency will be completely unaffected.
Will there be no end to govt attempts to break encryption?
TL;DR: No.
must be an agenda item
That was set to repeat each year. Nobody knows how to turn it off. The password for the account is forgotten and encrypted! That's it, they want the back door so they can log into the agenda account and turn off the agenda item repeat for encryption backdoors event... or so they say.
Assymetry, anyone?
Suppose people were to use private ciphers BEFORE messages enter the channel. It's widely held the private ciphers are crap. It's also widely believed that RSA, PGP etc have been cracked. So what is someone to do?
*
Well....EVEN IF PRIVATE CIPHERS ARE CRAP, they still have an excellent asymmetry property for their users:
- Users get real time communications
- Snoops have to wait till the cipher is cracked
*
Look up the Beale Papers (enciphed in a private cipher). Two of three messages have still not been deciphered (for more than a century). And that's with a book cipher -- widely held to be crap.
*
Anyway....the delay for the spooks puts them on the back foot....irrespective of the quality of the private cipher....and they may be on the back foot for long enough that the original message is well beyond its sell by date!!!!
Re: Assymetry, anyone?
"It's also widely believed that RSA, PGP etc have been cracked."
Any chance of a reputable reference for that? If the factorisation of large numbers has been 'cracked', that is a major event in mathematical logic / complexity theory. Probably get you an Abel or Turing prize, or at least a nomination.
You first
As soon as the government and intelligence services makes all their databases and emails available for public scrutiny, I will consider letting them look at all my data also. But it is of course pretty certain that they have *far* more incriminating data to hide than the average citizen, so that will never happen.
As usual, politicians asking for a magic unicorn to solve all their problems, so they don't have to pay money to have actual police officers doing proper work.
Because that would mean they'd have to pay for those police officers, which would mean it would come out of taxes, which might have to go up, which would mean rich people would go buy their cocaine and luxury yachts somewhere else and that would be a tragedy for the economy. Or something like that.