Russian Air Crash Investigation Changes The Encryption War

If intercepted communications prove an ISIS bomb caused crash in Egypt, it could be just the boost surveillance state advocates need. 

    
When US intelligence officials said “intercepted communications” are a basis for the early assessment that a bomb planted by the Islamic State may have doomed a Russian passenger jet over Egypt, they also may have given a huge boost to efforts to expand government-led surveillance in the name of counterterrorism.
“I think there is a possibility that there was a bomb on board,” President Barack Obama said, lending the commander in chief’s credibility to the theory. It’s the president’s first characterization of the disaster since British Prime Minister David Cameron said it was “more likely than not” that a bomb destroyed the airliner.
Egyptian officials continue to push back on the bomb theory, yet British Foreign Secretary Philip Hammond said, “Of course this will have a huge negative impact for Egypt. But with respect to [Egypt Foreign Ministry spokesman Ahmed Abouzeid,] he hasn’t seen all the information that we have.”

Consider that statement in the context of Cameron’s almost year-long crusade to strengthen the U.K. government’s surveillance capabilities and effectively shut down secure end-to-end user encryption both in the United Kingdom and beyond.

End-to-end user encryption refers to the ability of one person to share communications with another person over a digital interface, and only with that intended recipient. The message, whether an email, text or other communication, is “encrypted” by the sender and “decrypted” by the receiver using software. 

That means that the intermediary communications service provider, such as Apple, Google, Yahoo, or Facebook, can not decrypt the message, even under threat of incarceration or under pressure from a court. End-to-end user encryption, correctly implemented, is encryption without secret defects that allow someone to intercept those supposedly secure message. And it’s growing in popularity among users. In 2014, Apple and Google announced that iPhones and Android phones would begin to encrypt users’ data.

Just hours before the British government suspended flights over the Sinai, the UK government introduced a new law to weaken the type of end-to-end user encryption that would keep companies and law enforcement from being able to intercept messages. The so-called Investigatory Powers Bill also mandates that Internet companies retain detailed logs of their users’ Internet browsing activity for a year.

The bill claims to clarify a 2000 law and would require private companies to provide data and help authorities intercept communications, with a warrant, in addition to maintaining the ability to intercept and decrypt messages.
A UK government official explained it this way: “The Government is clear we need to find a way to work with industry as technology develops to ensure that, with clear oversight and a robust legal framework, the police and intelligence agencies can access the content of communications of terrorists and criminals in order to resolve police investigations and prevent criminal acts. That means ensuring that companies themselves can access the content of communications on their networks when presented with a warrant.’”

That matters in terms of the day’s headlines. The FBI and Cameron have accused the Islamic State of using popular encrypted-based apps to hide secret messages.

But human rights activists, journalists, and other security conscious individuals also use encryption to protect against data theft. Many computer science experts such as Bruce Schneier have argued for decades that wider access to encryption methods (without backdoors or built-in defects of the type the British government is seeking) would actually make the Internet far safer, including for people in countries like Iran and Syria who themselves are looking to reach out to US intelligence agencies. 

Wider use of encryption also likely would mean fewer instances of identify theft, missing data, and so-called phishing attacks that use personal information.
DefenseOne: http://bit.ly/1L1mzYI

 

 

« NATO’s role in the cyber domain is unclear.
New UK Surveillance Bill Appears In The Wake of Snowden »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

Perimeter 81 / How to Select the Right ZTNA Solution

Perimeter 81 / How to Select the Right ZTNA Solution

Gartner insights into How to Select the Right ZTNA offering. Download this FREE report for a limited time only.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Pondurance

Pondurance

Pondurance is an IT Security and Compliance company providing services in Cyber Security, Continuity, Compliance and Threat Management.

44CON

44CON

44CON is an Information Security Conference & Training event taking place in London. Designed to provide something for the business and technical Information Security professional.

Metasploit

Metasploit

Metasploit penetration testing software helps find security issues, verify vulnerabilities and manage security assessments.

Redscan Cyber Security

Redscan Cyber Security

Redscan Cyber Security is a Managed Security Services Provider (MSSP) that enables businesses to effectively manage their information security risks.

Computer & Communications Industry Association (CCIA)

Computer & Communications Industry Association (CCIA)

CCIA supports efforts to facilitate and streamline information sharing on cyber threats between the private sector and the Federal Government.

Thermo Systems

Thermo Systems

Thermo Systems is a design-build control systems engineering and construction firm. Capabilties include industrial control system cybersecurity.

Jscrambler

Jscrambler

Jscrambler addresses all your JavaScript and Web application protection needs.

Cyber Craft

Cyber Craft

CyberCraft is an innovative and dynamic software development, outsourcing and consulting company. Services offered include penetration testing.

Salt Security

Salt Security

Salt Security protects the APIs that are the core of every SaaS, web, mobile, microservices and IoT application.

International Accreditation Forum (IAF)

International Accreditation Forum (IAF)

The IAF is the world association of Conformity Assessment Accreditation Bodies. Its primary function is to develop a single worldwide programme of conformity assessment.

Privacera

Privacera

Privacera enables consistent data governance, security, and compliance across all your data services - on-premises and in the cloud - so you can maximize the value of your data.

Alacrinet

Alacrinet

Alacrinet is an IT and cyber security consultancy. From penetration testing to fully managed MSSP, our team is focused on knowing the latest threats, preventing vulnerabilities, and providing value.

BugDazz

BugDazz

BugDazz pentest as a service (PTaaS) platform helps bringing in real-time results, detail coverage, & easy remediation workflows with compliance-ready reports.

Association of Azerbaijani Cyber Security Organizations (AKTA)

Association of Azerbaijani Cyber Security Organizations (AKTA)

The Association of Azerbaijani Cyber Security Organizations (AKTA) is a non-commercial organization aimed at strengthening the country's cybersecurity system.

Anjuna Security

Anjuna Security

Software from Anjuna Security effortlessly enables enterprises to safely run even their most sensitive workloads in the public cloud.

DynTek

DynTek

DynTek delivers exceptional, cost-effective professional IT consulting services, end-to-end IT solutions and managed IT services.