Skip to main content

GCHQ’s not-so-smart idea to spy on encrypted messaging apps is branded ‘absolute madness’

Nobody wants to be a third wheel. Unless you’re a British spy.

Two of the most senior officials at British eavesdropping agency GCHQ say one way that law enforcement could access encrypted messages is to simply add themselves to your conversations.

“It’s relatively easy for a service provider to silently add a law enforcement participant to a group chat or call,” said Ian Levy, technical director of the U.K.’s National Cyber Security Center, and Crispin Robinson, cryptanalysis director at GCHQ, in an op-ed for Lawfare.

“The service provider usually controls the identity system and so really decides who’s who and which devices are involved — they’re usually involved in introducing the parties to a chat or call,” they said. “You end up with everything still being end-to-end encrypted, but there’s an extra ‘end’ on this particular communication.”

Law enforcement and intelligence agencies have long wanted access to encrypted communications, but have faced strong opposition to breaking the encryption for fears that it would put everyone’s communications at risk, rather than the terror suspects or criminals that the police primarily want to target. In this case, two people using an end-to-end encrypted messaging app would be joined by a third, invisible person — the government — which could listen in at will.

This solution, Levy and Robinson say, would be “no more intrusive than the virtual crocodile clips” that lawmakers have already authorized police to use to wiretap communications.

Presumably that would require compelled assistance from the tech companies that built the encrypted messaging apps in the first place, like Apple, Facebook’s WhatsApp, Signal, Wire and Wickr. That poses not only an ethical problem for the companies, which developed their own end-to-end encrypted services so that even they can’t access people’s communications, but also a technical one, which would require the government to ask a court to compel the companies to rework their own technologies to allow government spies in.

It wouldn’t be the first time the government’s pushed for compelled assistance.

Only recently that the U.S. government lost its bid to force Facebook to re-architect its Messenger app to allow the government to listen in on suspected gang members. And not just the U.S. or the U.K.. Russia, the west’s favorite frenemy, forced Telegram, another encrypted messaging app, to turn over its private keys in an effort to allow its intelligence agencies to snoop in on possible kompromat.

Suffice to say, the U.K.’s plan has drawn strong criticism.

And NSA whistleblower Edward Snowden, an outspoken commentator and critic of global surveillance, branded the move “absolute madness.”

“No company-mediated identity could be trusted,” said Snowden, suggesting that the move would effectively render the trust in any end-to-end encrypted messaging app redundant.

Exactly what the U.K.’s solution looks like isn’t entirely clear, but Mustafa Al-Bassam, a PhD student at University College London, said that the ability for users to verify their keys — which proves the identity of a person in a conversation — in an end-to-end messaging app is “is going to be increasingly important” to prevent government manipulation.

WhatsApp and Signal, for example, tell you when a user’s key changes, indicating that a new device is in use — and requires verification — or that a device has been manipulated by a third-party and that the conversation isn’t secure.

“They’re proposing to exploit the fact that users don’t verify each other’s public keys, and inject bad keys,” said Al-Bassam.



from TechCrunch https://ift.tt/2TZzesY
via IFTTT

Comments

Popular posts from this blog

Max Q: Psyche(d)

In this issue: SpaceX launches NASA asteroid mission, news from Relativity Space and more. © 2023 TechCrunch. All rights reserved. For personal use only. from TechCrunch https://ift.tt/h6Kjrde via IFTTT

Max Q: Anomalous

Hello and welcome back to Max Q! Last week wasn’t the most successful for spaceflight missions. We’ll get into that a bit more below. In this issue: First up, a botched launch from Virgin Orbit… …followed by one from ABL Space Systems News from Rocket Lab, World View and more Virgin Orbit’s botched launch highlights shaky financial future After Virgin Orbit’s launch failure last Monday, during which the mission experienced an  “anomaly” that prevented the rocket from reaching orbit, I went back over the company’s financials — and things aren’t looking good. For Virgin Orbit, this year has likely been completely turned on its head. The company was aiming for three launches this year, but everything will remain grounded until the cause of the anomaly has been identified and resolved. It’s unclear how long that will take, but likely at least three months. Add this delay to Virgin’s dwindling cash reserves and you have a foundation that’s suddenly much shakier than before. ...

What’s Stripe’s deal?

Welcome to  The Interchange ! If you received this in your inbox, thank you for signing up and your vote of confidence. If you’re reading this as a post on our site, sign up  here  so you can receive it directly in the future. Every week, I’ll take a look at the hottest fintech news of the previous week. This will include everything from funding rounds to trends to an analysis of a particular space to hot takes on a particular company or phenomenon. There’s a lot of fintech news out there and it’s my job to stay on top of it — and make sense of it — so you can stay in the know. —  Mary Ann Stripe eyes exit, reportedly tried raising at a lower valuation The big news in fintech this week revolved around payments giant Stripe . On January 26, my Equity Podcast co-host and overall amazingly talented reporter Natasha Mascarenhas and I teamed up to write about how Stripe had set a 12-month deadline for itself to go public, either through a direct listing or by pursuin...