Advertise On EU-Digest

Annual Advertising Rates
Showing posts with label encryption protocols. Show all posts
Showing posts with label encryption protocols. Show all posts

5/29/15

Internet: United Nations Deems Encryption Necessary For Freedom In Digital Age - by Jeff Stone

The United Nations' Office of the High Commissioner for Human Rights has issued a new report saying encryption, or encoding messages so that only the desired recipient can read them, is necessary to protect the right to freedom of expression throughout the world. The report went on to warn that countries around the world are increasingly engaged in efforts to weaken private Internet security.

The 18-page report from special rapporteur David Kaye was published Thursday and is due to be presented to the U.N. Human Rights Council in June.

“Encryption and anonymity, and the security concepts behind them, provide the privacy and security necessary for the exercise of the right to freedom of expression in the digital age,” Kaye wrote. “Such security may be essential for the exercise of other rights, including economic rights, privacy, due process, freedom of peaceful assembly and association, and the right to bodily integrity.”

The U.N. approved of decryption as long as it's done on a “case-by-case basis.” This is only the latest update in an ongoing debate over the best way for countries to balance security and personal privacy. Almost every prominent member of the U.S. law enforcement and intelligence communities have claimed that their inability to access users' smartphones and electronic communication – including users suspected of no wrongdoing – creates a threat for all Americans.

Most notably, Apple and Google entered the conversation when, by making it impossible for themselves to decode users' smartphone passcodes, they turned on encryption for millions of phones across the world. FBI Director James Comey was furious, and suggested that lawmakers may introduce a law to force companies to install so-called surveillance backdoors to give the government a point of entry.
Apple, Google and others signed a letter to President Obama earlier this month asking him to forego any executive action that would make back doors mandatory. 

Read more: United Nations Deems Encryption Necessary For Freedom In Digital Age

4/24/15

The Internet: The Only Email System The NSA Can't Access - by Hollie Slade

When the NSA surveillance news broke last year it sent shockwaves through CERN, the particle physics laboratory in Switzerland. Andy Yen, a PhD student, took to the Young at CERN Facebook group with a simple message: “I am very concerned about the privacy issue, and I was wondering what I could do about it.”

There was a massive response, and of the 40 or so active in the discussion, six started meeting at CERN’s Restaurant Number 1, pooling their deep knowledge of computing and physics to found ProtonMail, a gmail-like email system which uses end-to-end encryption, making it impossible for outside parties to monitor.

Encrypted emails have actually been around since the 1980s, but they are extremely difficult to use. When Edward Snowden asked a reporter to use an end-to-end encrypted email to share details of the NSA surveillance program the reporter couldn’t get the system to work, says Yen.

“We encrypt the data on the browser before it comes to the server,” he explains. “By the time the data comes to the server it’s already encrypted, so if someone comes to us and says we’d like to read the emails of this person, all we can say is we have the encrypted data but we’re sorry we don’t have the encryption key and we can’t give you the encryption key.”

“We’ve basically separated the message that’s encrypted apart from the key – all the encryption takes place on your computer instead of our servers, so there’s no way for us to see the original message.”
This is different from all other systems, says Yen. While Gmail has implemented some encryption, they still have the encrypted message and the key to decrypt the message.

While half the team is now at MIT, some are still in Switzerland where the ProtonMail’s servers are housed for extra protection. “One of the key things we want to do is control our servers and make sure all the servers are in Switzerland which will increase privacy because Switzerland doesn’t do things like seize servers or tape conversations,” says Yen. This will help avoid a situation where the U.S government could forcibly shut them down, says Yen, similar to what happened to Lavabit last year.

Read more: The Only Email System The NSA Can't Access - Forbes

9/8/13

Internet encryption protocols compromised by US - NSA and British - GCHQ, according to leaked documents - by James Vincent

Intelligence agencies from Britain and the US have cracked many of the encryption protocols used to secure communications on the internet, according to documents leaked by the NSA whistleblower Edward Snowden.


The fresh information reveals that the US National Security Agency has worked in collaboration with the the UK's GCHQ to compromise online privacy.

"For the past decade, NSA has lead [sic] an aggressive, multi-pronged effort to break widely used internet encryption technologies,” reads a GCHQ document from 2010. "Vast amounts of encrypted internet data which have up till now been discarded are now exploitable."

Various methods have been pursued in order to break or circumvent the security protecting the personal data of billions of people.

These include breaking encryption with “brute force” attacks conducted by super computers; using court-orders to force companies into handing over master keys to their software, and one program that “actively engages US and foreign IT industries to covertly influence and/or overtly leverage their commercial products' designs”.

This latter scheme, named the Sigint Enabling Project, costs the NSA $254.9m a year according to a 2013 budget document provided by Snowden. Sigint stands for "signal intelligence". An internal memo from the agency records the reaction from British analysts: “Those not already briefed were gobsmacked!”

“These frightening revelations imply that the NSA has not only pursued an aggressive program of obtaining private encryption keys for commercial products […] but that the agency has also attempted to put backdoors into cryptographic standards designed to secure users' communications,” said the Electronic Frontier Foundation in response.

“Additionally, the leaked documents make clear that companies have been complicit in allowing this unprecedented spying to take place, though the identities of cooperating companies remain unknown.”
In response to the leaked documents - which were handed from Mr Snowden to The Guardian, The New York Times and the non-profit news site Pro Publica - Google have claimed that no such "active engagement" has taken place.

Note EU-Digest: Strange and maybe even suspicious is that the EU Parliament and EU Commission seem to be taking these allegations for granted and so far have hardly said anything about it . 

As for the US foreign policy team,  they might benefit to take note of the biblical quote "And why beholdest thou the mote that is in thy brothers eye, but considerest not the beame that is in thine owne eye?" Matthew 7, verse 3

Read more: Encryption protocols compromised by NSA and GCHQ, according to leaked Edward Snowden documents - UK - News - The Independent