ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Story: Government to force handover of encryption keys

  • Previous comment

Posted by: Anonymous (Friday 19 May 2006, 10:33 PM)

  • Reply

Hmm... and what, exactly, does this "order to seize" actually do to protect people from terrorism? Does it prevent terrorists from cloning citizens' phones and using them to communicate with other terrorists? Or criminals for that matter?

Does this actually safeguard ANYONE?

What prevents people from just generating thousands upon thousands of keys? Perhaps millions of keys?

Officer: I need to access your protected data... please give me your key.

Individual: Sure. Here is a hard drive filled with all of the keys I use. Not sure which goes where, but here are my keys. (300GB hard drive with over a hundred million keys)

Imagine that data is encrypted 1-3 times by each key(100-300 million times encrypted) and even one key is wrong/missing? What then? How long would it take to access the data?

Worse... what prevents criminals and terrorists from deliberately generating such overly encrypted data with mind numbingly large numbers of keys? Just downright bog down the workflow of data decryption.

This kind of "blind reasoning" or "panic reasoning" is hurtful to the local economy and over time, erodes faith in the governing body's ability to think rationally and plan for the country's safety.

This kind of thing will discourage businesses from:
- travelling there
- setting up shop there
- accepting customers from there or who travel there

Imagine the headache when even 1% of your customer base requests a new key to be generated because their existing one got seized and they no longer feel their information is safe?

What if this happened on a daily basis?

The other question is whether the police officers are qualified to handle the keys themselves? Are they trained and certified as people who are capable of handling encrypted keys?

If I was a company, I would immediately move my business out of that region. It is a legal liability to me and my customers to have personal keys revealed.

So does this give the police the power to take peoples' passwords to online accounts as well? To corporate accounts? In the event "terrorist" or "criminal" data is stored there?

Do the people making these laws even think about the consequences!?

  • Previous comment

  • Reply to this comment
  • Return to story
  • Report this as offensive


Full Talkback thread


Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment