Wrong time to weaken encryption, UK IT chartered institute tells government
- Reference: 1681817230
- News link: https://www.theregister.co.uk/2023/04/18/wrong_time_to_weaken_encryption/
- Source link:
BCS, formerly the British Computer Society, has warned that weakening encryption of secure messaging apps in online safety legislation would damage public trust in technology.
The controversial [1]Online Safety Bill is set to be heard in the House of Lords for scrutiny this week. It sets out wide-ranging measures designed to protect people, particularly children, in their online lives.
[2]
However, critics have argued that — however well-intentioned — the legislation could create a back door for governments to read encrypted messages.
[3]
[4]
In a statement, BCS chief executive Rashik Parmar, said: “It’s the wrong time to weaken encryption when it is vital to public trust in the value of technology. Every genuine tech professional wants children to be safe online; but we need to guard the basic security that underpins everyone’s privacy.
“There is grave concern that the Online Safety Bill’s requirements around identifying illegal content could break the principle of end-to-end encryption with the promise of a magical backdoor. Once a backdoor has been compromised, data and content protected by the encryption becomes accessible. This is exactly what many bad actors would welcome.
'If privacy is outlawed, only outlaws will have privacy'
In an [5]open letter this morning, addressed to "anyone who cares about safety and privacy on the internet," end-to-end-encrypted communication platforms Element, Session, Signal, Threema, Viber, WhatsApp and Wire urged UK.gov to reconsider its current plans.
They called the bill an "unprecedented threat to the privacy, safety and security of every UK citizen and the people with whom they communicate around the world" adding that the move would embolden "hostile governments who may seek to draft copy-cat laws."
Global providers of end-to-end encrypted products and services cannot weaken the security of their products and services to suit individual governments. There cannot be a "British internet," or a version of end-to-end encryption that is specific to the UK.
The UK Government must urgently rethink the Bill, revising it to encourage companies to offer more privacy and security to its residents, not less. Weakening encryption, undermining privacy, and introducing the mass surveillance of people's private communications is not the way forward.
“Building confidence in technology is a global priority in 2023. A bill aimed at keeping us safe online should protect encrypted messaging,” he said.
We've been here before
This is not the British government's first encryption-breaking rodeo. It has for years called upon tech companies to break encryption so law enforcement can listen in: [6]most notably former Home Sec and then PM Theresa May , and later [7]former Home Sec Amber Rudd and [8]former UK Home Secretary Priti Patel .
Erstwhile Prime Minister David Cameron even proposed [9]banning online messaging applications that support end-to-end encryption in 2015.
What about this bill?
The Online Safety bill legislation is set to give media regulator Ofcom powers to make platforms identify and remove child abuse content. Any compnies refusing to comply could face large fines.
In February, encrypted chat service Signal [10]said it would put an end to its UK operations if the Online Safety Bill was enacted in its current state. Proposals for device-side scanning — designed to protect children from harmful content — break the security of end-to-end encryption at the same time, it argued.
There cannot be a 'British internet,' or a version of end-to-end encryption that is specific to the UK
The legislation contains what critics have called " [11]a spy clause " [PDF]. It requires companies to remove child sexual exploitation and abuse (CSEA) material or terrorist content from online platforms "whether communicated publicly or privately." As applied to encrypted messaging, that means either encryption must be removed to allow content scanning or scanning must occur prior to encryption.
Meredith Whittaker, president of the Signal Foundation, told The Register : "Many millions of people globally rely on us to provide a safe and secure messaging service to conduct journalism, express dissent, voice intimate or vulnerable thoughts, and otherwise speak to those they want to be heard by without surveillance from tech corporations and governments."
[12]Children should have separate sections in social media sites, says UK coroner
[13]Cooler heads needed in heated E2EE debate, says think tank
[14]What's that? Encryption's OK now? UK politicos Brexit from Whatsapp to Signal
[15]'Real' people want govts to spy on them, argues UK Home Secretary
[16]Five Eyes nations stare menacingly at tech biz and its encryption
"We have never, and will never, break our commitment to the people who use and trust Signal. And this means that we would absolutely choose to cease operating in a given region if the alternative meant undermining our privacy commitments to those who rely on us."
In response to Whittaker's remarks, Dr Monica Horten, policy manager for freedom of expression at Open Rights Group, also urged the UK government to drop the clause.
[17]
When the legislation was first proposed in March, 2022, Nadine Dorries, digital secretary at the time, said, “Tech firms haven’t been held to account when harm, abuse and criminal behaviour have run riot on their platforms. Instead, they have been left to mark their own homework. If we fail to act, we risk sacrificing the wellbeing and innocence of countless generations of children to the power of unchecked algorithms.” ®
Get our [18]Tech Resources
[1] https://bills.parliament.uk/bills/3137
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZD6@o6W75LILs8myKyuaVQAAAME&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZD6@o6W75LILs8myKyuaVQAAAME&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZD6@o6W75LILs8myKyuaVQAAAME&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://threema.ch/es/blog/posts/online-safety-bill
[6] https://www.theregister.com/2018/01/25/uk_prime_minister_encryption/
[7] https://www.theregister.com/2017/10/03/amber_rudd_still_does_not_understand_encryption/
[8] https://www.theregister.com/2019/07/31/home_sec_priti_patel_five_eyes_encryption_controversy/
[9] https://www.theregister.com/2015/01/12/iranuk_in_accord_as_pm_promises_to_block_encrypted_comms_after_election/
[10] https://www.theregister.com/2023/02/25/signal_uk_online_safety_bill/
[11] https://blogs.soas.ac.uk/cop/wp-content/uploads/2022/12/SOAS-ICOP-Briefing-Online-Safety-Bill.pdf
[12] https://www.theregister.com/2022/10/18/social_media_separate/
[13] https://www.theregister.com/2022/04/05/e2ee_rusi/
[14] https://www.theregister.com/2019/12/20/uk_conservatives_brexit_from_whatsapp_to_signal/
[15] https://www.theregister.com/2017/08/01/amber_rudd_on_encryption/
[16] https://www.theregister.com/2017/06/13/five_eyes_stare_menacingly_at_encryption/
[17] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZD6@o6W75LILs8myKyuaVQAAAME&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[18] https://whitepapers.theregister.com/
No need to break encryption - just ask Isabel Oakeshott...
Lets start by making all UK politician's calls and messages public.
Nothing to hide, nothing to fear?
Re: Lets start by making all UK politician's calls and messages public.
> Nothing to hide, nothing to fear?
Please, we all have curtains; don't trot this out.
Privacy means being able to choose the audience, timing and manner of revealing something, or choosing to keep it secret forever.
HT Cory Doctorow
They know what the problem is. Your mistake is in thinking the goal is to protect children.
The 5th of November
The television is already listening and watching. To further the cause you should all have to install cameras in all bedrooms. A lot of violence is committed in the bedroom. Therefore, it is only just to make sure that it gets recorded and used as evidence against you perverts. The listening and viewing cars roaming the streets will make sure that every bad act, physically or verbally, is appropriately punished. Close all dark alleys. Make sure you are being controlled.
And don't forget to blow up parliament.
So this is only to be used to catch criminals? Won’t work.
Sure, you might get a few technologically inept petty criminals - but you won’t get the big guys. The terrorists. The kingpins of drugs, trafficking, pornography etc. Those guys are already on the dark web, those guys are already using messaging systems rolled for the purpose, built using open-source encryption algorithms - algorithms which will continue to exist outside of this legislation, and hence still inaccessible to law enforcement.
The only thing you can absolutely guarantee will happen from this legislation is that you will make the lives of the criminals easier, and I’m not just talking about governments. Those backdoors won’t stay secret for long, and then organised crime will have a field day mining the data that we all thought was private.
It's also fairly easy to use 3rd party tools like Oversec to encrypt messages/media before sending them over a messaging app. This bill would do nothing to prevent that.
That's part of my argument. Let's assume we trust the Government of the UK to not abuse this (bear with me, I know it's a stretch...). So UK Govt, police, MI5 can read our messages but that's OK, because they're the "good guys". America sees this and enacts similar legislation, so they now have access to the back door. Hrm, Ok, but we're at least allies, so that's not too bad... Then China. Then Russia. Then a corrupt regime which is repressing its populace and arresting/killing dissidents. If you aim to allow the "good guys" access but not the "bad guys", you have to make moral judgements which companies are notoriously bad at.
Once you've hit that breadth of access, the backdoor isn't secure and the entire system is being snooped by, well, just about everyone.
As you say, anyone who is vaguely tech savvy will have a better, secure solution immune to these back doors.
Let's assume we trust the Government of the UK to not abuse this
Only if we also assume I'm a billionaire and as fit and healthy as I was in my 20s(*).
(*) Icon nearer to ground truth.
Remember the Government's thinly-veiled campaign to discredit end-to-end encryption?
https://noplacetohide.org.uk/
Yes, you read that correctly, https.
Whose Encryption Might Be "Weakened"?
Quote: "....weaken encryption...."
But whose encryption would that be?
Here at Linux Mansions all commumication with my buddies uses private encryption:
- Diffie/Hellman
- 30,000 bit safe primes
- Multiple encryption passes
- So....in case you need to to be told....NO PERSISTENT OR PUBLISHED KEYS anywhere
How is the government going to "weaken" encryption and decryption which ONLY OCCURS ON OUR OWN end point devices?
OK....we sometimes send out privately encrypted messages over Signal or WhatsApp......but we really don't care if those services use "weak" encryption..........
......because (obviously) when the spooks decrypt Signal or WhatsApp.....all they find is our privately encrypted messages (see above!).
We can't see a problem. Perhaps someone out there can explain.
Re: Whose Encryption Might Be "Weakened"?
Doesn’t affect me so I don’t care?
That is childish, and foolish in the extreme. There are a lot of reasons someone so *clever* as you should care:
1) If you find yourself in a society where encryption is banned, and you’re one of the only ones not sending plaintext, youll be very easy to see and as only criminals and kiddie fiddlers would need to, you may find yourself having trouble explaining what you were doing, with no way to prove innocence.
2) You might have friends or family who are harmed by personal, formally thought to be private communications made public or used for blackmail or ransom
3) Once this is allowed, it’s very easy to extend the powers by just saying “look we already do this here and here and it’s fine, so yes we’re going to scan every electronics device and find those creeps still hiding”, at which point you’ll need to up your game and start writing your own firmware and trusting your counterparts are doing it correctly too, because you will not be able to trust your devices as they come, regardless of software
4) Yellow stars - have some compassion, it’ll probably put you on the right side of history
Re: Whose Encryption Might Be "Weakened"?
@claimed
The AC does make an interesting point.....namely that some group or another using their own technology.....is scarecly being "childish"!!!!
Perhaps the point is that it's "childish" to rely for privacy on a single point of failure (e.g. Signal).....
....as opposed to taking personal responsibility.....and not subcontracting the responsibility to Signal (or GCHQ!).
It's a curious argument that people who take personal responsibility for their own affairs are automatically to be regarded as "creeps".
Just saying!!
It's all somebody else's fault
“Tech firms haven’t been held to account when harm, abuse and criminal behaviour have run riot on their platforms."
"Government hasn't been held to account when harm, abuse and criminal behaviour have run riot on their streets"
Put in security holes, and I do no business with a UK company for any reason what so ever. I will not compromise on my security to appease British bean counters and fools.
@Groo_The_Wanderer
Quote: "... a UK company..."
Well......then there's companies in the USA, or in Israel, or elesewhere........companies which might have MUCH more clout than the British.
I think your revulsion for a specific country (the UK) might be a bit of a security distraction (for you!).
When I opened an international investment bank account through a UK branch, a few days later I started to get targeted investment spam to my never spammed email address before. The sender email was not related to the bank.
UK regulators seem inept. Let them do their existing jobs well before they start to regulate something more serious.
Well criminals don't obey the laws anyway hence the name so what we assume they'll magically obey the laws when communicating with their peers? All this does it make it easier for us to fall prey to criminals, the ONLY mitigation is strong encryption and nothing else. Whoever came up with this legislation is a moron of apocalyptic proportions and too stupid to do anything other bang rocks together and they might even be too thick even for that.
Yeah, undermine country cyber-security by "protecting children".
There cannot be a "British internet"
Home secretary : "A British Internet! What a great idea! Why did nobody think of this before? Let's take back control of the internet here too, we don't want to use this foreign muck anymore with its rules set by unelected non-British bureaucrats, let's pass a retained IP rules law to abolish them all, and make a nice insecure Britternet (for the plebs, not us, obvs). Pull up the digital drawbridge! Freedom to go our own insecure way!"
2 weeks later : "Hey, where's all the money in my online bank account gone?"
AI to identify you all
The proposed initiative is scary, because AI systems already demonstrate super-human ability to "connect points". So when messages are not encrypted, the system will be able to identify and track every person. Their plans, their personality, their weaknesses, their secrets. Guess what happens when some crazy politicians decide to take over the country?
Encryption is an important step to protect from totalitarian control.
Doh!
That secret removable floorboard looks more attractive by the day
Freudian Slap
I read "If we fail to act, we risk sacrificing the wellbeing and ignorence of countless generations of children to the power of unchecked algorithms".
Awks
"If $FOO is outlawed only outlaws will have $FOO" is a problematic argument. You only have to look at it's best-known usage. The fact that it's convincing to the gun lobby but not to me shows the likely reaction of others who don't see encryption as a good thing. Yes, we know why they are wrong. But the gun-nuts know why I'm wrong too.
My oft-repeated argument for this...
...is sure, why not?
But...
It applies to every person, company and government body with a mandatory jail sentence for those not using it.
With NO exceptions. None.
So - banks, the military, the police and every goddamn sleazeball of a politician.
After all if you have nothing to hide...
Watch it go away then.
Utterly pointless, anyone involved in child porn will be able to find a few pounds a month for a VPN. if they aren't using one already
In case people don't know about it
There's a technique called [1]chaffing (with winnowing to undo) that gives secrecy(*) without encryption, just a requirement for higher bandwidth.
(*) To some level, the same as encryption.
[1] https://en.wikipedia.org/wiki/Chaffing_and_winnowing
Sir Humphrey knew all about the Politician's Fallacy
We must do something.
This is something.
Therefore, we must do this.
Lets start by making all UK politician's calls and messages public.
Perhaps then they might see the issue.