Russian Air Crash Investigation Changes The Encryption War

If intercepted communications prove an ISIS bomb caused crash in Egypt, it could be just the boost surveillance state advocates need. 

    
When US intelligence officials said “intercepted communications” are a basis for the early assessment that a bomb planted by the Islamic State may have doomed a Russian passenger jet over Egypt, they also may have given a huge boost to efforts to expand government-led surveillance in the name of counterterrorism.
“I think there is a possibility that there was a bomb on board,” President Barack Obama said, lending the commander in chief’s credibility to the theory. It’s the president’s first characterization of the disaster since British Prime Minister David Cameron said it was “more likely than not” that a bomb destroyed the airliner.
Egyptian officials continue to push back on the bomb theory, yet British Foreign Secretary Philip Hammond said, “Of course this will have a huge negative impact for Egypt. But with respect to [Egypt Foreign Ministry spokesman Ahmed Abouzeid,] he hasn’t seen all the information that we have.”

Consider that statement in the context of Cameron’s almost year-long crusade to strengthen the U.K. government’s surveillance capabilities and effectively shut down secure end-to-end user encryption both in the United Kingdom and beyond.

End-to-end user encryption refers to the ability of one person to share communications with another person over a digital interface, and only with that intended recipient. The message, whether an email, text or other communication, is “encrypted” by the sender and “decrypted” by the receiver using software. 

That means that the intermediary communications service provider, such as Apple, Google, Yahoo, or Facebook, can not decrypt the message, even under threat of incarceration or under pressure from a court. End-to-end user encryption, correctly implemented, is encryption without secret defects that allow someone to intercept those supposedly secure message. And it’s growing in popularity among users. In 2014, Apple and Google announced that iPhones and Android phones would begin to encrypt users’ data.

Just hours before the British government suspended flights over the Sinai, the UK government introduced a new law to weaken the type of end-to-end user encryption that would keep companies and law enforcement from being able to intercept messages. The so-called Investigatory Powers Bill also mandates that Internet companies retain detailed logs of their users’ Internet browsing activity for a year.

The bill claims to clarify a 2000 law and would require private companies to provide data and help authorities intercept communications, with a warrant, in addition to maintaining the ability to intercept and decrypt messages.
A UK government official explained it this way: “The Government is clear we need to find a way to work with industry as technology develops to ensure that, with clear oversight and a robust legal framework, the police and intelligence agencies can access the content of communications of terrorists and criminals in order to resolve police investigations and prevent criminal acts. That means ensuring that companies themselves can access the content of communications on their networks when presented with a warrant.’”

That matters in terms of the day’s headlines. The FBI and Cameron have accused the Islamic State of using popular encrypted-based apps to hide secret messages.

But human rights activists, journalists, and other security conscious individuals also use encryption to protect against data theft. Many computer science experts such as Bruce Schneier have argued for decades that wider access to encryption methods (without backdoors or built-in defects of the type the British government is seeking) would actually make the Internet far safer, including for people in countries like Iran and Syria who themselves are looking to reach out to US intelligence agencies. 

Wider use of encryption also likely would mean fewer instances of identify theft, missing data, and so-called phishing attacks that use personal information.
DefenseOne: http://bit.ly/1L1mzYI

 

 

« NATO’s role in the cyber domain is unclear.
New UK Surveillance Bill Appears In The Wake of Snowden »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Pondurance

Pondurance

Pondurance is an IT Security and Compliance company providing services in Cyber Security, Continuity, Compliance and Threat Management.

CyTech Services

CyTech Services

CyTech provides unique services and solutions complemented with professional subject matter experts to both the Federal and Commercial sectors.

International Federation of Robotics (IFR)

International Federation of Robotics (IFR)

The International Federation of Robotics connects the world of robotics around the globe. Our members come from the robotics industry, industry associations and research & development institutes.

SEEK

SEEK

SEEK create world-class technology solutions to address the needs of job seekers and hirers across multiple sectors including cybersecurity.

Cyber Threat Alliance

Cyber Threat Alliance

CTA is working to improve cybersecurity of our digital ecosystem by enabling near real-time cyber threat information sharing among companies and organizations in the cybersecurity field.

Utility Cyber Security Forum

Utility Cyber Security Forum

The Utility Cyber Security Forum offers a focused venue in which utility executives can network one-on-one with colleagues facing issues in protecting against cyber attacks.

Octane OC

Octane OC

OCTANe is building the SoCal of tomorrow. We drive innovation and growth by connecting people, resources and capital. Our Incubator focus is FinTech, Data Analytics and Cybersecurity.

Option3

Option3

Option3 (formerly Option3Ventures - O3V) primarily seek control investments in the growing cybersecurity mid-market, seeking to build champions with the scale to bring cutting-edge products to market.

Tyler Technologies

Tyler Technologies

Tyler Technologies is a leading provider of end-to-end information management solutions and services for local governments.

ITTAS

ITTAS

ITTAS is a multidisciplinary company specializing in information security and software and hardware protection software.

Fluid Attacks

Fluid Attacks

Fluid Attacks specialize in red team operations as well as technology development that continuously enhance our security testing services.

Noblis

Noblis

Noblis is a dynamic science, technology, and strategy organization dedicated to creating forward-thinking technical and advisory solutions in the public interest.

GuardYoo

GuardYoo

GuardYoo's SaaS platform allows cybersecurity professionals to perform Compromise Assessment remotely from anywhere in the world.

People Driven Technology

People Driven Technology

People Driven Technology is a customer-obsessed organization. We leverage our decades of business, technology, and engineering experience to deliver outcomes for our clients.

Salus Cyber

Salus Cyber

Salus is a provider of world-class cyber security services, enabling our clients to identify and manage their cyber risks proactively and effectively.

Systems Engineering

Systems Engineering

Systems Engineering is a SOC 2, Type 2-certified IT strategy and managed technology services provider.