Russian Air Crash Investigation Changes The Encryption War

If intercepted communications prove an ISIS bomb caused crash in Egypt, it could be just the boost surveillance state advocates need. 

    
When US intelligence officials said “intercepted communications” are a basis for the early assessment that a bomb planted by the Islamic State may have doomed a Russian passenger jet over Egypt, they also may have given a huge boost to efforts to expand government-led surveillance in the name of counterterrorism.
“I think there is a possibility that there was a bomb on board,” President Barack Obama said, lending the commander in chief’s credibility to the theory. It’s the president’s first characterization of the disaster since British Prime Minister David Cameron said it was “more likely than not” that a bomb destroyed the airliner.
Egyptian officials continue to push back on the bomb theory, yet British Foreign Secretary Philip Hammond said, “Of course this will have a huge negative impact for Egypt. But with respect to [Egypt Foreign Ministry spokesman Ahmed Abouzeid,] he hasn’t seen all the information that we have.”

Consider that statement in the context of Cameron’s almost year-long crusade to strengthen the U.K. government’s surveillance capabilities and effectively shut down secure end-to-end user encryption both in the United Kingdom and beyond.

End-to-end user encryption refers to the ability of one person to share communications with another person over a digital interface, and only with that intended recipient. The message, whether an email, text or other communication, is “encrypted” by the sender and “decrypted” by the receiver using software. 

That means that the intermediary communications service provider, such as Apple, Google, Yahoo, or Facebook, can not decrypt the message, even under threat of incarceration or under pressure from a court. End-to-end user encryption, correctly implemented, is encryption without secret defects that allow someone to intercept those supposedly secure message. And it’s growing in popularity among users. In 2014, Apple and Google announced that iPhones and Android phones would begin to encrypt users’ data.

Just hours before the British government suspended flights over the Sinai, the UK government introduced a new law to weaken the type of end-to-end user encryption that would keep companies and law enforcement from being able to intercept messages. The so-called Investigatory Powers Bill also mandates that Internet companies retain detailed logs of their users’ Internet browsing activity for a year.

The bill claims to clarify a 2000 law and would require private companies to provide data and help authorities intercept communications, with a warrant, in addition to maintaining the ability to intercept and decrypt messages.
A UK government official explained it this way: “The Government is clear we need to find a way to work with industry as technology develops to ensure that, with clear oversight and a robust legal framework, the police and intelligence agencies can access the content of communications of terrorists and criminals in order to resolve police investigations and prevent criminal acts. That means ensuring that companies themselves can access the content of communications on their networks when presented with a warrant.’”

That matters in terms of the day’s headlines. The FBI and Cameron have accused the Islamic State of using popular encrypted-based apps to hide secret messages.

But human rights activists, journalists, and other security conscious individuals also use encryption to protect against data theft. Many computer science experts such as Bruce Schneier have argued for decades that wider access to encryption methods (without backdoors or built-in defects of the type the British government is seeking) would actually make the Internet far safer, including for people in countries like Iran and Syria who themselves are looking to reach out to US intelligence agencies. 

Wider use of encryption also likely would mean fewer instances of identify theft, missing data, and so-called phishing attacks that use personal information.
DefenseOne: http://bit.ly/1L1mzYI

 

 

« NATO’s role in the cyber domain is unclear.
New UK Surveillance Bill Appears In The Wake of Snowden »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Black Duck Software

Black Duck Software

Black Duck Hub allows organizations to manage open source code security as well as license compliance risks.

Rockwell Automation

Rockwell Automation

Rockwell Automation offer industrial security solutions to protect the integrity and availability of your complex automation solutions.

Cyberint

Cyberint

Cyberint, the Impactful Intelligence company, fuses open-deep-and darkweb Threat Intelligence with Attack Surface Management to deliver maximum protection from external threats.

Calyptix Security

Calyptix Security

Calyptix Security helps small and medium offices secure their networks so they can raise profits, protect investments, and control technology.

Envieta

Envieta

Envieta is a leader in cryptographic solutions. From server to sensor, we design and implement powerful security into new or existing infrastructure.

SkyePoint Decisions

SkyePoint Decisions

SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure and Operations, and Applications Development and Maintenance IT service provider.

Naq Cyber

Naq Cyber

Naq is the number one platform for SMEs looking to become legally compliant and protect against cybercrime and other data-related incidents.

Infostream

Infostream

Infostream is a leading integrator of Digital Transformations Solutions (DTS); Public, Private, and Hybrid Cloud; Cybersecurity; Data Integrity; DevOps, DevSecOps, and Infrastructures.

Center for Information Security Awareness (CFISA)

Center for Information Security Awareness (CFISA)

CFISA was formed by a group of academics, security and fraud experts to explore ways to increase security awareness among audiences, including consumers, employees, businesses and law enforcement.

inWebo

inWebo

inWebo is the specialist in multi-factor strong authentication (MFA). We guarantee the security of data and identities in a digital world with increasingly important economic and political stakes.

ITC Federal

ITC Federal

ITC Federal delivers IT cybersecurity assessment services to support agencies in meeting their security strategies and federal security compliance goals.

NexGen Cyber

NexGen Cyber

NexGen Cyber helps customers in commercial SMB markets with IT security, security integration, service management, outsourced service transition, and transformative security solutions.

Dexian

Dexian

Dexian is a leading provider of staffing, IT, and workforce solutions with nearly 12,000 employees and 70 locations worldwide.

Excite Cyber

Excite Cyber

Excite Technology Services (formerly Cipherpoint) is focused on improving the security posture of our customers.

Ingenics Digital

Ingenics Digital

Ingenics Digital is a recognized initiator and leading service provider in the areas of software development and embedded systems.

True North Solutions

True North Solutions

True North Solutions provides a wide range of fully customized, vendor-neutral industrial engineering and OT automation solutions to companies across North America and around the world.