Страницы

Showing posts with label Encryption. Show all posts
Showing posts with label Encryption. Show all posts

Tuesday, March 3, 2020

Encryption

PROJECT RUBICON: THE NSA SECRETLY SOLD FLAWED ENCRYPTION FOR DECADES

There have been a few moments in the past few years, when a conspiracy theory is suddenly demonstrated to be based in fact. Once upon a time, it was an absurd suggestion that the NSA had data taps in AT&T buildings across the country. Just like Snowden’s revelations confirmed those conspiracy theories, a news in February confirmed some theories about Crypto AG, a Swiss cryptography vendor.

The whole story reads like a cold-war era spy thriller, and like many of those novels, it all starts with World War II. As a result of a family investment, Boris Hagelin found himself at the helm of Aktiebolaget Cryptograph, later renamed to Crypto AG (1952), a Swedish company that built and sold cipher machines that competed with the famous Enigma machine. At the start of the war, Hagelin decided that Sweden was not the place to be, and moved to the United States. This was a fortuitous move, as it allowed Hagelin to market his company’s C-38 cipher machine to the US military. That device was designated the M-209 by the army, and became the standard in-the-field encryption machine.

Wednesday, February 26, 2020

Encryption



MI5 chief asks tech firms for 'exceptional access' to encrypted messages

Sir Andrew Parker, the director general of MI5.
MI5’s director general has called on technology companies to find a way to allow spy agencies “exceptional access” to encrypted messages, amid fears they cannot otherwise access such communications.
Sir Andrew Parker is understood to be particularly concerned about Facebook, which announced plans to introduce powerful end-to-end encryption last March across all the social media firm’s services.
In an ITV interview to be broadcast on Thursday, Sir Andrew Parker says he has found it “increasingly mystifying” that intelligence agencies like his are not able to easily read secret messages of terror suspects they are monitoring.

Thursday, February 20, 2020

Encryption

Hagelin and Friedman: The Gentlemen’s Understanding Behind “The Intelligence Coup of the Century”

CX-52Reporting last week in The Washington Post and Germany’s ZDF public television channel mentioned a 1951 meeting between Crypto AG’s Boris Hagelin and American cryptographer William Friedman, the noted cryptanalyst who was acting as a representative of U.S. intelligence, at Washington D.C.’s Cosmos Club. This meeting reportedly built the foundation of a “gentlemen’s understanding” between Hagelin and the United States to control the company’s cryptographic devices. This agreement would ultimately lead to the joint CIA/BND purchase of Crypto AG upon Hagelin’s retirement in 1970.
Documents from William Friedman’s collection shed light on the years before Hagelin’s retirement and the level of cooperation between the two men. Discussions begin on the issue of surplus M-209 cryptographic devices, designed by Hagelin, in the aftermath of World War II (Documents 1, 5, 6). Both sides sought to control this surplus stock, U.S. intelligence agencies to restrict cryptographic capability to friendly nations, and Hagelin to avoid flooding his own market.

Sunday, February 16, 2020

Encryption

Swiss Crypto AG spying scandal shakes reputation for neutrality


A Swiss soldier stands in front of a Swiss flag
It's hard to exaggerate just how much the Crypto AG scandal has shaken Switzerland.
For decades, US and German intelligence used this Swiss company's encoding devices to spy on other countries, and the revelations this week have provoked outrage.
From the Cold War into the 2000s, Crypto AG sold the devices to more than 120 governments worldwide. The machines were encrypted but it emerged this week that the CIA and Germany's BND had rigged the devices so they could crack the codes and intercept thousands of messages.
Rumours had circulated in the past but now everybody knows.

Why Swiss neutrality matters

There are only a handful of countries on the planet that have chosen neutrality; Austria is one, Sweden another. But no country has made a status symbol out of neutrality like the Swiss.
Now that the Crypto AG scandal has emerged in all its tawdry detail, there's not a newspaper or broadcaster in the country that is not questioning Switzerland's neutrality.

Saturday, April 20, 2019

Encryption

15 Tech Experts Predict The Next Big Topics In Encryption And Cybersecurity


uncaptioned
As businesses continue to digitize data and operations and consumers add more and more tech to their homes, encryption and cybersecurity are hotter topics now than they’ve ever been. A growing range of Internet of Things (IoT) tech is increasing the stakes, as any security protocol is only as strong as the weakest link.
Everyone from the tech developers creating new products to the consumers who use them needs to be aware of the latest news in encryption and cybersecurity. To help you stay abreast of coming changes, we asked members of Forbes Technology Council to offer their predictions on the next big news items in encryption and cybersecurity.
1. Multi-Tiered Authentication
Generic encryption apps like Authy and Google Authenticator have helped consumers expand their static passwords to more secure two-step verification using time-based codes generated by standardized algorithms. As consumers use more online services, a new multi-tiered authentication is expected to emerge to further protect more critical access, like online banking and e-commerce. - Ahmad (Al) FaresCelitech Inc.

Thursday, April 11, 2019

Encryption

Evolving Quantum Computing Threat is Taken Seriously

The advanced computing capabilities of quantum computers will render most traditional encryption protocols used today obsolete. The US government is already preparing contingencies for how to defend its current IT assets and equipment from the threat.
Quantum computers exploit quantum mechanical phenomena to solve mathematical problems that are difficult or intractable for conventional computers. If large-scale quantum computers are ever built, they will be able to break many of the public-key cryptosystems currently in use, according to csrc.nist.gov.
The US National Institute of Standards and Technology (NIST) wants to develop new encryption standards designed to protect the federal government from new and emerging cybersecurity threats.
The agency spent much of the past year evaluating 69 algorithms for its Post Quantum Cryptography Standardization project, designed to protect the machines used by federal agencies today from the encryption-breaking tools of tomorrow.

Sunday, January 20, 2019

Encryption

Serious Security: What 2000 years of cryptography can teach us


These days, a lot of your data gets encrypted when you save it to disk or send it over the internet.
The data gets decrypted again when you read it back in or after it’s received at the other end.
For that, you need some sort of cryptographic algorithm – what’s known in the jargon as a symmetric cipher or secret-key encryption.
Symmetric ciphers use the digital equivalent of a key, typically a string of characters, to lock and unlock the data.
In this article, we’ll take a journey through the history of symmetric ciphers during the pen-and-paper era, before mechanical and electronic encryption devices came onto the scene.
From Julius Caesar in the first century BC to Joseph Mauborgne at the end of the second millennium AD, we’ll look at:
  • How each generation of algorithms worked.
  • Why they fell by the wayside.
  • What was better – or not! – about what came next.
The good news is that you won’t need to wade through any advanced mathematics to appreciate this fascinating story…

Monday, August 20, 2018

Encryption

You could soon spend 10 years in Australian jail if you don’t hand over your phone password to cops


© Christian Ohde / Global Look Press
New Australian bill introduces some of the toughest legislation anywhere in the world for refusing to hand over personal data, while other Western countries are scrambling for their own solutions.
Existing legislation already allows for imprisonment for up to two years for failing to give investigators access when serious crime is involved, but the new Assistance and Access bill, which has gone out for public consultation, before being voted on later on this year, raises the punishment to 10 years.
The Department of Home Affairs says the document is seeking a “reasonable and proportionate response” to such violations.
“Encryption and other forms of electronic protection… are being employed by terrorists, child sex offenders and criminal organisations to mask illegal conduct. The exploitation of modern communications technology for illicit ends is a significant obstacle to the lawful access of communications by Australia’s law enforcement and national security agencies,” says its intro.
To give weight to its proposal, the ministry gives an example of a pedophile rapist, who was using mobile messengers to offer drugs to underage teens in exchange for sex. 

Monday, July 23, 2018

Encryption

The quantum meltdown of encryption

Digital SecurityThe world stands at the cusp of one of the greatest breakthroughs in information technology. Huge leaps forward in all fields of computer science, from data analysis to machine learning, will result from this breakthrough. But like all of man’s technological achievements, from the combustion engine to nuclear power, harnessing quantum comes with potential dangers as well. Quantum computers have created a slew of unforeseen vulnerabilities in the very infrastructure that keeps the digital sphere safe.
The underlying assumption behind nearly all encryption ciphers used today is that their complexity precludes any attempt by hackers to break them, as it would take years for even our most advanced conventional computers to do so. But quantum computing will change all of that.
Quantum computers promise to bring computational power leaps and bounds ahead of our most advanced machines. Recently, scientists at Google  began testing their cutting edge 72 qubit quantum computer. The researchers expect to demonstrate with this machine quantum supremacy, or the ability to perform a calculation impossible with traditional computers.

Wednesday, May 23, 2018

Encryption

FBI Over-Counted Encrypted Phones Connected To Crimes — By A Lot

The FBI significantly over-counted the number of encrypted phones it says are connected to ongoing criminal investigations but remain inaccessible to investigators without back door access.
For about seven months, the bureau has been telling Congress and the public that potential evidence on nearly 7,800 blocked devices continues to elude investigators. The statistic has been cited repeatedly by multiple officials and lawmakers to demonstrate what they say is the growing threat encryption software combined with a reluctance by manufacturers to provide a key, poses to national security and public safety. But in reality, the true number of devices that have impeded investigations, is likely to be a fraction of that, the FBI acknowledged in a statement Tuesday.
"The FBI's initial assessment is that programming errors resulted in significant over-counting of mobile devices reported through [the Operational Technology Division's] databases," the FBI said.

Monday, April 16, 2018

Encryption

Lawmakers Question FBI’s Push for Backdoors in Encrypted Devices

Картинки по запросу fbi
A bipartisan crew of 10 House lawmakers took FBI Director Christopher Wray to task Friday following an inspector general report that found the bureau rushed to court to force Apple to help it break into the encrypted iPhone used by San Bernardino shooter Syed Farook in 2015 without exploring other options.

Ultimately, the FBI withdrew its case against Apple when an unnamed third party offered to sell the bureau a tool to break into the phone without Apple’s help—a tool that a separate FBI division knew was nearly complete when the FBI first brought the Apple case, the IG found.

The rush to litigation, detailed in the IG report, suggests the FBI hasn’t been completely honest about the threat that warrant-proof encryption systems pose to national security, the lawmakers write.

Wray and his predecessor James Comey have warned that such end-to-end encryption systems allow criminals and terrorists to “go dark” online. The FBI has said it encountered 7,800 locked mobile devices that it could not access last year.

Thursday, March 15, 2018

Encryption

IARPA director: Encryption-busting quantum computers coming in near future


The head of the intelligence community’s advanced research agency is looking at new encryption standards that can withstand future breakthroughs in quantum computing.
Jason Matheny,  the director Intelligence Advanced Research Projects Activity (IARPA), told reporters Wednesday that his agency, one of the leading authorities on quantum computing, could someday — pending a couple of major developments — crack some of the most sophisticated encryption available today.
However, Matheny said, that’s assuming the United States remains the global front-runner in encryption technology. Allowing countries like Russia or China to take the lead, he added, could have major implications for the future of cybersecurity.
“It wouldn’t be good, and it would be good not to be surprised. One of the reasons that we invest is so that we understand where the state of the art is, understand a bit about what the timelines are so that we can deploy quantum-resistant encryption when it’s critical,” Matheny said during a meeting of the Defense Writers Group.

Saturday, March 3, 2018

Encryption

How Government Lost the Crypto Wars (At Least for Now)


Article ThumbnailForty-two years after unbreakable encryption was first conceived, these tools are more widespread than ever before. One milestone came in 2016, when the world's largest messaging service—WhatsApp—announced it would offer default end-to-end encryption on all communications. In other words, the messages can be read only by the senders and recipients; even the platform provider can't access them.
Law enforcement and intelligence agencies are still reckoning with this new reality. For decades, they demanded that tech companies hand over private data on their users, sometimes without obtaining warrants. So companies like Apple changed their policies so individual users were the only ones holding the keys to their data.
This new era of consumer privacy led to a standoff in 2016, when the Federal Bureau of Investigation (FBI) demanded access to an encrypted iPhone belonging to Sayed Farook, a deceased terrorist from San Bernardino, California. Farook and his wife, Tashfeen Malik, had killed 14 people at a holiday office party in December 2015.
The FBI wanted Apple to write software that would weaken the iPhone's built-in security. Apple refused, saying that such flawed software would jeopardize the security of its customers, who number in the hundreds of millions. Once a back door was created, the company claimed, the FBI could use it on similar phones—and it could be leaked to hackers or foreign enemies. "It is in our view the software equivalent of cancer," Apple CEO Tim Cook told ABC News.
Plenty of consumer data is still unencrypted and can be accessed by large tech companies. From Facebook to Gmail, many online platforms give law enforcement access to their users' private conversations. But the growing use of end-to-end encryption, by Apple in particular, represents a drastic shift.

Thursday, January 11, 2018

Encryption

FBI chief calls encryption a ‘major public safety issue’

FBI Director Christopher A. Wray on Tuesday renewed a call for tech companies to help law enforcement officials gain access to encrypted smartphones, describing it as a “major public safety issue.”
Wray said the bureau was unable to gain access to the content of 7,775 devices in fiscal 2017 — more than half of all the smartphones it tried to crack in that time period — despite having a warrant from a judge.
“Being unable to access nearly 7,800 devices in a single year is a major public safety issue,” he said, taking up a theme that was a signature issue of his predecessor, James B. Comey.
“We’re not interested in the millions of devices of everyday citizens,” he said in New York at Fordham University’s International Conference on Cyber Security. “We’re interested in those devices that have been used to plan or execute terrorist or criminal activities.”

Sunday, August 20, 2017

Encryption

Insider trading schemes using encrypted apps alarm FBI


The Federal Bureau of Investigation is growing concerned that Wall Street traders are turning to encrypted apps to hide illicit communications from internal compliance programmes and regulators. Encryption is “a growing problem overall,” John Casale, an assistant special agent in charge of complex financial crimes in the Manhattan field office told the FT. “New technology comes out and you know it’s going to be applied and it could be applied in a way to engage in fraud, money laundering, and insider trading.” The first indication that applications, such as WhatsApp, Signal or Telegram that allow for secure end-to-end communications, are being used by white collar offenders inside big banks came to light late Wednesday in a largely unnoticed insider trading case.

Monday, July 10, 2017

Encryption

UK's ex-spy chief warns Amber Rudd's plan to pass new smartphone encryption law is dangerous

amber-rudd.jpg
The UK’s ex-spy chief has warned the Home Secretary’s plans to force smart phone apps such as WhatsApp to hand over encrypted messages are unworkable and dangerous.
Robert Hannigan, the former head of GCHQ, ridiculed Amber Rudd’s threat to pass new laws to build “back doors” into secret messages as doomed to fail.
“Encryption is an overwhelmingly good thing - it keeps us all safe and secure,” Mr Hannigan said.

Tuesday, August 23, 2016

Encryption

France, Germany push for greater access to encrypted content in wake of attacks


France and Germany said they want to compel operators of mobile messaging services to allow access to encrypted content to aid terrorism investigations, joining forces after a series of deadly attacks in both countries.

French intelligence services, on high alert since attackers killed scores of civilians in Paris in November and in Nice in July, are struggling to intercept messages from Islamist militants.
Many of the groups now favour encrypted messaging services over mainstream social media, with jihadist Islamic State a big user of such apps, investigators in several countries have said.
French Interior Minister Bernard Cazeneuve said the European Commission should draft a law obliging operators to cooperate in judicial investigations into tracking down terrorists.
“If such legislation was adopted, this would allow us to impose obligations at the European level on non-cooperative operators,” he told a joint conference with his German counterpart in Paris.

Thursday, August 11, 2016

Encryption

How the Government Is Waging Crypto War 2.0


Fast forward 20 years from the Bernstein ruling to the aftermath of the San Bernardino attacks. In the weeks that followed the shooting, federal investigators were faced with a problem: the iPhone 5C used by Farook was encrypted and the investigators were unable to access the data stored on the phone. This prompted FBI officials to contact Apple with requests to help them unlock the phone by creating a version of iOS with a backdoor that would allow the government access to the data on the phone. Apple denied their requests on the grounds that it would never compromise the security of its projects and so the FBI applied for a court order which would force Apple to create the requested software.

Saturday, July 16, 2016

Encryption

UK surveillance bill includes powers to limit end-to-end encryption


The UK government has explicitly confirmed that a surveillance bill now making its way through the second chamber could be used to require a company to remove encryption. And even, in some circumstances, to force a comms service provider not to use end-to-end encryption to secure a future service they are developing. The details were revealed during debate of the Investigatory Powers Bill at a committee session in the House of Lords this week.
This cements concerns over the phrasing of a clause in the bill that refers to the ‘removal of electronic protection’, which critics, including from the technology and security industries, have long been warning risks outlawing the use of strong encryption in the UK.

Wednesday, July 13, 2016

Encryption

Putin gives federal security agents two weeks to produce ‘encryption keys’ for the Internet


Password
After signing controversial anti-terrorist legislation earlier today, President Putin ordered the Federal Security Service (the FSB, the post-Soviet successor to the KGB) to produce encryption keys to decrypt all data on the Internet. According to the executive order, the FSB has two weeks to do it. Responsibility for carrying out Putin's instructions falls on Alexander Bortnikov, the head of the FSB.
The new “anti-terrorist” laws require all “organizers of information distribution” that add “additional coding” to transmitted electronic messages to provide the FSB with any information necessary to decrypt those messages. It's still unclear what information exactly online resources are expected to turn over, given that all data on the Internet is encoded, one way or another, and in many instances encryption keys for encrypted information simply don't exist.