US law enforcement agencies are making the argument (for example at recent Senate hearings) that they need some technological mechanism to give them access to all communications channels and stored data, however encrypted. Similar demands are being heard in other nations.
Without going into any detail on these issues, I wanted to share a recent very clear and concise report titled "Keys Under Dormats: Mandating Insecurity" from a group that includes a number of the world's leading experts on various aspects of computer security. This report, which has gotten some media attention recently, including coverage in the New York Times, briefly reviews the long history of this debate and the current situation in the context of technical realities as well as trust and risk issues.
The report can be found here, along with an abstract and author list:
http://dspace.mit.edu/handle/1721.1/97690I would note that at least in the United States, the calls for access seem to be very much focused on claimed law enforcement needs (with the Director of the FBI being the most prominent proponent of such access); the broader context of national security, encompassing not just law enforcement but the security, integrity and resilience of public and private information systems, as well as economic interests of industry and the concerns of the intelligence communities, leads to a much more confusing, complex and nuanced landscape. For a taste of these complexities, one place to start might be two blog entries by Bruce Schneier, one of the group of authors of the report, and the various links and commentary connected to them.
The Risks of Mandating Backdoors in Encryption Products - Schneier on Security
Tuesday, a group of cryptographers and security experts released a major paper outlining the risks of government-mandated back-doors in encryption products: Keys Under Doormats: Mandating insecurity by requiring government access to all data and communications, by Hal Abelson, Ross Anderson, Steve Bellovin, Josh Benaloh, Matt Blaze, Whitfield Diffie, John Gilmore, Matthew Green, Susan Landau, Peter Neumann, Ron Rivest, Jeff Schiller, Bruce Schneier, Michael Specter, and Danny Weitzner. Abstract:...
What is the DoD's Position on Backdoors in Security Systems? - Schneier on Security
In May, Admiral James A. Winnefeld, Jr., vice-chairman of the Joint Chiefs of Staff, gave an address at the Joint Service Academies Cyber Security Summit at West Point. After he spoke for twenty minutes on the importance of Internet security and a good national defense, I was able to ask him a question (32:42 mark) about security versus surveillance: Bruce Schneier: Iād like to hear you talk about this need to get beyond signatures and the more robust cyber defense and ask the industry to provid...
Clifford Lynch Director, CNI
You just read issue #1076 of CNI-ANNOUNCE. You can also browse the full archives of this newsletter.