Hide BestNetTech is off for the holidays! We'll be back soon, and until then don't forget to check out our fundraiser »

Just To Be Safe, UK Government To Confiscate Cryptographic Keys

from the trust-us,-well-keep-it-secure dept

As new UK regulations come into force, businesses may be compelled to hand over cryptographic keys to the police force. The explanation, surprisingly enough, is that the government needs the keys in order to effectively combat pedophiles, terrorists, and any other public menace that a politician can dream up. Defenders of the actions say there is a difference between handing over the keys and being required to decrypt private data, but it’s not clear why the key can’t be handed over after the police suspect illicit communication. Besides, a centralized collection of cryptographic keys would be quite the mother lode for cyber-criminals to attack. Even if they’re impenetrable from the outside, they’ll be hard to protect from an internal attack (e.g. a spy). Should the regulations be executed, the big loser could be the UK, as companies keep important information and keys outside of its borders. As hard as it is to imagine, it seems a regulation designed to keep people safer from predators might actually heighten their risk.


Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “Just To Be Safe, UK Government To Confiscate Cryptographic Keys”

Subscribe: RSS Leave a comment
20 Comments
I, for one says:

Faulted reasoning

This says some important things.

Firstly it an admission that GCHQ/MI5 etc lack the computer capabilities and/or resources to crack everyday crypotgraphy. That means that PGP etc really is pretty good.

Secondly it is, on the face of it quite sensible. It places the responsibility for data with the data owner. Many companies simply can’t manage their internal security (hell some can’t even manage basic website security) so they place their keys in escrow. The law is designed to pave the way for forcing the accused to get those keys back not tie up police time and resources chasing rainbows.

The requirement is not an a priori arrangement as many people will assume. You don’t have to hand over keys for all and any encrypted data you have. It is a measure to be used when a crime is under investigation not an open door to give the police unfettered access to company and private data.

But, it falls down on two points.

It creates a crime of not handing over the keys. There are many legitimate reasons to not have keys. Any good security policy rotates keys on a weekly or daily basis for non retained info. And why would you keep old keys, especially if you are up to no good? Thus it makes no distinction between well intentioned good security policy and suspicious behaviour.

It’s based on the investigators assumption. There is no distinction between random noise and encrypted data. If the police come across a block of noise from a random wipe how are they to identify it? They ask the user for the key, and of course there is none, but then a criminal would say that wouldn’t they. Thus, again, there is no technical way to differentiate between illegal and legal activity. One is therefore guilty of a crime (refusing to hand over non-existant keys) purely on the basis of an arbitary accusation.

In summary it has the usual effect of making those who are truly criminal but well informed safer (they will rotate and destroy keys for nefarious reasons) while exposing the innocent to greater chance of injustice and abuse.

Now I’ll tell you, I know a few good cops. They hate this crap. They are overwhelmed, lacking in expertise and resources and completely befuddled by the technicalities and the laws. Most (all normal police but a few uber geek detectives) want to abandon what they see as a huge waste of time chasing technological evidence and go back to old fashioned methods of psychology and human investigation. That’s how you catch criminals.

Which is why this law was obviously not created by the needs of criminal investigation. It is an admission by government that they powerless against criminals who use sophisticated methods and an attempt to change the burden of proof. They need to acknowledge that they have lost this battle and shift resources back into manpower where it can be effective (observation, infiltration, case building).

|333173|3|_||3 says:

Re: Citizens of the UK

But all the leader of major parties are Scots, and they have different laws anyway, so what chance do everyone else have. All they do is pass one set of laws in Scotland and a different set in Westminster, just like with university fees. the public won’t act because too many ppl are ignorant sheep, just like in the USA or Aus.

Anonymous Coward says:

given how laws in one country often turn up in another, I suspect it’s only a matter of time before similiar legislation turns on in the US. Given the amount of stories I’ve read about government compromised systems, or occasionally sheer incompetence, I don’t have to worry about terrorist and theives. The government is doing most of their legwork for them.

qkslvrwolf (user link) says:

Stupid and stupid

First, the idea is stupid because only people with nothing to hide are going to give up their keys. Everyone else isn’t. So you’re going to have access to the information you don’t need. The poster above pretty much outlined all the reasons this is ridiculous.

Also stupid, however, is number 14. Hey dipshit…they never had guns. The laws preventing your average everyday citizen and/or criminal from getting guns came early…before guns were really common. Thus…NO ONE got guns, and they still don’t have them. Criminals or “good guys” alike.

This obviously won’t work in the US because we all already have guns, so only the law abiding citizens would be likely to give them up. Which would be kinda dumb. In fact, its almost the same thing as the crypt keys.

Dee says:

(__/)
(=’.’=)This is Bunny. Copy and paste bunny
(“)_(“)into your signature to help him gain world domination. 😀

._…|..____________________, ,
……/ `—___________—-_____|] = = = D
…../_==o;;;;;;;;_______.:/
…..), —.(_(__) /
….// (..) ), —-”
…//___//
..//___//
.//___//

……………. __
………..__.(__)..__
……….(__)l…..l(__)
……….l.=.ll..=.ll.=.l.__
……….l….ll…..ll….l(__)
……….l.=.ll==ll.=.ll.=.l
……….l….ll…..ll….ll….l
__…….l.=.ll==ll.=.ll.=.l
l]…)….l………………….l
l….|….l………………….l
(……_./………………….l
…………………………..l
………………………….l
…………………………/
…_…………………../
…l…………………l

Dee says:

(__/)

(=’.’=)This is Bunny. Copy and paste bunny

(“)_(“)into your signature to help him gain world domination. 😀

._…|..____________________, ,

……/ `—___________—-_____|] = = = D

…../_==o;;;;;;;;_______.:/

…..), —.(_(__) /

….// (..) ), —-”

…//___//

..//___//

.//___//

……………. __

………..__.(__)..__

……….(__)l…..l(__)

……….l.=.ll..=.ll.=.l.__

……….l….ll…..ll….l(__)

……….l.=.ll==ll.=.ll.=.l

……….l….ll…..ll….ll….l

__…….l.=.ll==ll.=.ll.=.l

l]…)….l………………….l

l….|….l………………….l

(……_./………………….l

…………………………..l

………………………….l

…………………………/

…_…………………../

…l…………………l

Dee says:

(__/)

(=’.’=)This is Bunny. Copy and paste bunny

(“)_(“)into your signature to help him gain world domination. 😀

._…|..____________________, ,

……/ `—___________—-_____|] = = = D

…../_==o;;;;;;;;_______.:/

…..), —.(_(__) /

….// (..) ), —-”

…//___//

..//___//

.//___//

……………. __

………..__.(__)..__

……….(__)l…..l(__)

……….l.=.ll..=.ll.=.l.__

……….l….ll…..ll….l(__)

……….l.=.ll==ll.=.ll.=.l

……….l….ll…..ll….ll….l

__…….l.=.ll==ll.=.ll.=.l

l]…)….l………………….l

l….|….l………………….l

(……_./………………….l

…………………………..l

………………………….l

…………………………/

…_…………………../

…l…………………l

Add Your Comment

Your email address will not be published. Required fields are marked *

Have a BestNetTech Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

BestNetTech community members with BestNetTech Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the BestNetTech Insider Shop »

Follow BestNetTech

BestNetTech Daily Newsletter

Subscribe to Our Newsletter

Get all our posts in your inbox with the BestNetTech Daily Newsletter!

We don’t spam. Read our privacy policy for more info.

Ctrl-Alt-Speech

A weekly news podcast from
Mike Masnick & Ben Whitelaw

Subscribe now to Ctrl-Alt-Speech »
BestNetTech needs your support! Get the first BestNetTech Commemorative Coin with donations of $100
BestNetTech Deals
BestNetTech Insider Discord
The latest chatter on the BestNetTech Insider Discord channel...
Loading...