(BEING CONTINUED FROM 25/06/16)
European Commission Pushing For Encryption Backdoors
The debate surrounding encryption backdoors has been raging on for years with governments (that typically don’t really understand the things they are pushing for) requesting all software have government ‘secured’ backdoor keys.
This is now getting more serious in Europe with the EC actually forcing the issue (in a passive aggressive kind of way for now) and promising legislation to back it up within 2 years or so.
The European Commission will in June push for backdoor access to encryption used by apps, according to EU Justice Commissioner Věra Jourová.
Speaking publicly, and claiming that she has been pushed by politicians across Europe, Jourová said that she will outline “three or four options” that range from voluntary agreements by business to strict legislation.
The EC’s goal is to provide the police with a “swift and reliable” way to discover what users of encrypted apps have been communicating with others.
“At the moment, prosecutors, judges, also police and law enforcement authorities, are dependent on whether or not providers will voluntarily provide the access and the evidence. This is not the way we can facilitate and ensure the security of Europeans, being dependent on some voluntary action,” Jourová said, according to EU policy site Euractiv.
Typically governments will use the threat of legislation to push companies into agreeing to offer what they want voluntarily. But Jourová clearly expects some significant pushback from the tech industry – particularly US corporations such as Facebook and Apple – and so argued that the voluntary, non-legislative approaches would only be provisional in order to get to “a quick solution,” with laws coming later.
The intended message is that the EC is not bluffing and although it will take a few years to pass such legislation, it is prepared to do so, and may do so regardless of what app-makers offer.
The issue is always the same, if the government has a universal backdoor key for an app (let’s say for example Whatsapp) and they get hacked, and all the bad guys get hold of this Whatsapp universal decryption key – how many people do you think are going to die? Yah, a lot.
But the governments always say nooo, that won’t happen, we won’t/don’t/can’t get hacked – it’s totally safe. Or they’ll describe some kind of hair-brained protection scheme that makes no sense.
The announcement comes close on the heels of a number of aggressive pushes by European governments against social media companies.
Earlier this month, the German government proposed a €50m fine if companies like Facebook and Twitter do not remove “obvious” criminal content within 24 hours. A few days later, the EC said it was going to insist that social media companies change their terms and conditions to remove various efforts to insulate them legally from content issues – such as the requirement for anyone to sue them in a California court rather than in their home country.
And one day after the March 22 murderous attack in the heart of London, the UK government was publicly critical of the failure of companies like Google and Facebook to remove extremist content on the internet, arguing that they “can and must do more.”
That was followed shortly after by UK Home Secretary Amber Rudd specifically highlighting Facebook-owned chat app WhatsApp and arguing that the authorities must be given access to messages sent by the Westminster attacker over the service.
The debate over encryption has been going on for well over a year and until recently was dominated by fights in the United States, most notably between the FBI and Apple over access to an iPhone used by a shooter in San Bernardino, California.
For anyone in the tech or security communities, we will always be fundamentally against this as it breaks the very base tenets of using cryptography properly in the first place.
But from a government perspective, it’s a trade-off, security and/or privacy of the masses vs getting critical information on terrorists or from other threats.
At the heart of the matter though, nothing has changed: tech companies and security experts say that if crypto backdoors are created, it will be impossible to ensure that only the “good guys” can use this special access, and thus will undermine end-to-end encrypted systems and encrypted storage. Meanwhile politicians and law enforcement insist they don’t care how it’s done, they want to be able to access people’s private communications and stored data, particularly if they have a warrant regarding suspected criminal behavior. ®
Correction: updated to add
The original version of this article stated that the EC was looking to pass legislation providing it with backdoor access to encryption.
A spokesperson from the EC got in touch to say that Jourová’s words had been misinterpreted and there is no plan to introduce legislation covering encryption. The proposed laws will instead cover faster access to material held in the cloud in different jurisdictions. Material that, presumably, they expect to be unencrypted.
That clarification came on the same day that UK home secretary Amber Rudd also appeared to back away from her demand that law enforcement be given access to encrypted communications on apps such as WhatsApp.
(TO BE CONTINUED)