News: 1606485665

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

UK infoseccer launches petition asking government not to backdoor encryption

(2020/11/27)


A UK infosec bod has launched a petition asking the government if it would please drop its plans to install backdoors in end-to-end encryption.

Application security specialist Sean Wright's [1]Parliamentary petition comes as an expression of uneasiness at long-signalled plans for British state agencies to sidestep encryption and enable snooping on private citizens' online conversations at will.

The so-called "ghost user" proposal, the latest incarnation of which was dreamt up by folk from eavesdropping agency GCHQ, [2]prompted an international backlash last year from luminaries such as Bruce Schneier and Richard Stallman. Critics have warned that a backdoor, once discovered, is open to everyone – regardless of whether they have "permission" to use it or not.

Wright told The Register today of his anti-backdoor petition: "From what's been proposed, I don't see a way of protecting privacy without having an impact on others, especially legitimate users."

What's most concerning about the backdoor plan is what happens when it is discovered and abused, he said. "If I have an abusive partner in law enforcement, will they then be able to use [the backdoor] against me as their attack vector? We've seen politicians doing different things for different reasons, how do we ensure that's not abused? Also how do we ensure it's protected? Only legitimate users should get access to it, so it's going to be another system that could potentially be compromised."

"I do have concerns that if we do put some type of mechanism into place which would allow law enforcement to be able to read this private data, it may jeopardise legitimate use of encryption for ordinary law abiding citizens," said Wright on his [3]personal blog .

The Five Eyes spying alliance (UK, US, CAN, AUS, NZ) plus their new pals Japan and India renewed global calls to break encryption by [4]claiming the world's children would come to harm if it wasn't removed , in so many words.

Jake Moore, formerly of Devon Police and now with Slovakian infosec biz ESET, opined to The Register : "Old fashioned police tactics cannot decrypt these encrypted messages easily, which puts many cases on hold. However, putting the internet in jeopardy by demanding the relaxation of encryption is not the answer, so a petition is regretfully needed. Getting the numbers up is another quest altogether and until people fully understand what the government are after, we may sadly struggle to get the signatures up."

Encryption remains a target for state agencies

The National Crime Agency (NCA) claimed in a [5]press release earlier this week that a child abuser could not have been caught if Facebook had deployed end-to-end encryption.

It also revealed that the perp was identified and caught through what sounds like old-fashioned policing methods: a Facebook account he used to contact his victims was linked to a pay-as-you-go mobile phone number; that phone was topped up at a shop with CCTV, giving police a visual ID of the perp; and when they figured out his name and arrested him, the phone was found in his bedroom. He then pleaded guilty. In addition, as the NCA said: "IP addresses used to commit the offences resolved to his house."

US authorities helped the NCA by obtaining data from Google, while Facebook passed details of the criminal's chats to US cops, who forwarded it to their British counterparts.

The NCA's Rob Jones, director of threat leadership, said: "It's chilling to think [sexual predator] Wilson wouldn't have been caught if Facebook had already implemented their end-to-end encryption plans which will entirely prevent access to message content."

The agency insisted to The Register that the investigation would never have been possible without secretly reading the contents of Wilson's messages.

Meanwhile, the French police [6]hack of encrypted chat service Encrochat , something gleefully (and rightfully) leapt upon by British law enforcement, seems to have been made possible not because encryption had to be broken but because the French man-in-the-middle'd an Encrochat server. From there police deployed malicious updates across the Encrochat network to dump unencrypted images of users' handsets back to servers they controlled, bypassing encryption altogether by simply reading off chats direct from user endpoints.

Western law enforcement agencies maybe do not struggle with encryption to the extent that they claim. Those who believe in keeping themselves and their loved ones safe online may, therefore, find Wright's petition a useful outlet in the current climate. ®

Get our [7]Tech Resources



[1] https://petition.parliament.uk/petitions/554027

[2] https://www.theregister.com/2019/05/30/tech_hits_back_at_gchq_ghost_user_privacy_buster/

[3] https://blog.sean-wright.com/why-im-opposed-to-encryption-backdoor-proposals/

[4] https://www.theregister.com/2020/10/19/e2e_break_five_eyes/

[5] https://www.nationalcrimeagency.gov.uk/news/man-admits-96-online-sexual-offences-against-51-young-boys

[6] https://www.theregister.com/2020/11/13/encrochat_hack_judicial_review_judgment/

[7] https://whitepapers.theregister.com/

Quite literally...

Tigra 07

A case of "Oh noes! Won't someone please think of the children!"

I have signed it

alain williams

I am telling others to sign it as well.

Re: I have signed it

Nunyabiznes

I would sign it if I were in the correct jurisdiction!

Re: I have signed it

UCAP

I've signed it.

Breaking encryption not needed

Wellyboot

The predator Wilson was traced using the age old 'follow the crumbs' approach giving enough circumstantial evidence for a search warrant. His phone was then found & seized, this was enough (easily identified endpoint) for another warrant requesting ISPs,Carriers & social media firms to hand over the logs. At this point, it wouldn't take very long to identify all of his victims and direct evidence from victims gives an easy conviction.

At no point did reading the live messages need to be done, unless plod is saying that they were already doing this to everyone already (how else could they find him?) and no complaint was made by a victim or online child protection group before they took an interest in his activities.

If this is the level of argument that the NCA comes up with as an excuse for removing any serious security from personal communications its pathetic, they can already find out easily enough all the details relating to any message (except the actual content) for the last year and proceed from that with warranted activities for the rest.

Re: Breaking encryption not needed

Anonymous Coward

...for the last year.

What planet are you on? They don't delete anything, ever. Right to be forgotten is a date field in your file telling them not to provide you with any data older than your request date/time.

Re: Breaking encryption not needed

Wellyboot

I was merely pointing out the current 'legal' position where ISPs etc. must keep all data for a year should plod come calling with a warrant, so plenty of opportunity for legal investigation.

If the ISPs choose to to keep data for longer, that's a commercial decision. If plod collects and keeps data forever that won't make any difference to the backdoored encryption debate.

Re: Right to be forgotten is a date field in your file

Anonymous Coward

As we've been implementing it (miscellaneous banking industry) it not only stops data from being provided in any kind of information requests but also from being user-searchable past the forget-about-me date, though it will linger forever in the database (or its backups) and can be retrieved by IT at any given time - following proper channels, hopefully.

It's easy

smudge

All he has to do is talk to Sir Graham Brady and Sir Ian Duncan Smith and Steve Baker and all the Tory MPs who are currently fuming at the authoritarian attacks on our freedom and human rights that are the covid restrictions.

They will of course instantly understand that backdooring encryption is also an attack on our liberty and rights, and will organise a rebellion to ensure that any proposal to backdoor encryption will never get through Parliament.

Won't they?

Pie in the sky?

Long John Silver

This measure, being based on 'noble' sentiments, may well gain traction during these times of a punch drunk compliant parliament. Few MPs are likely to understand the technical issues involved or to bother getting up to speed. The large Conservative majority makes passage of legislation almost inevitable. Labour MPs wearing 'decency' on their sleeves could support it; perhaps some will indulge in the same inane kneeling gesture they did for BLM.

Yet one must question just how much damage this proposal actually could do if implemented. Commercial purveyors of social communication platforms within 'Five Eyes' jurisdictions shall be obliged to obey. For speakers of English and other European languages these platforms (e.g. Facebook) predominate. However, people intent upon conducting their private and working lives secure from intrusion don't use these means to socialise and to do business. Unencumbered encrypted communication shall continue using VPN, secure email services, and messaging applications procured from foreign sources. Long established open source tools for specific purposes, e.g. PGP, will continue in use as shall transfer of divers 'content' in compressed encrypted format. Then there is Tor and a number of distributed peer to peer networks all at advanced stages of maturity.

Internet recruitment and predation upon children must in the main depend upon mass social media. Hence, in theory neutering encryption on these media would accrue benefits. As for other criminal enterprise fruits from encryption back doors will be minimal in number and in terms of sophistication of crime; this because criminals along with sensible honest folk have other means to converse.

Even benefit from detecting crime against children is moot with respect to enacting back door access to 'conversations'. It might help gathering incriminating evidence against those already suspect but fishing expeditions into a huge accumulating pile of decrypted communications doesn't seem worth the bother.

Governments appear to place huge faith in technological solutions to problems better tackled by other means. We are seeing this now with respect to Covid-19: a pretty useless phone 'app', testing asymptomatic people, and the proposed "Operation moonshot". Concerning crime they would do better by increasing provision of traditional policing methods; when so, technology becomes a support rather than driver of activity.

Crime dependent upon the Internet is largely abstract until it impacts the physical world. Connection between the two realms is tenuous until people seek physical contact, pay for services with money, and deliver physical items. That recognition has enabled police forces to prosecute vendors and recipients of 'deals' transacted in the quite secure environment of Tor. Conventional policing through steady observation of nefarious activity with cross-referencing within and between Tor and the open Internet has enabled investigators to pick upon human errors by criminals which give clues to identity.

The shifts of Fortune test the reliability of friends.
-- Marcus Tullius Cicero