Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 22 March, 2023
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Events
    • Most Inspiring Women in Cyber 2022
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Events
    • Most Inspiring Women in Cyber 2022
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

National Security or Collective Privacy. FBI or Apple. Where Do You Stand?

by The Gurus
April 13, 2016
in News
Share on FacebookShare on Twitter

Despite the lengthy legal arguments, we now know that the FBI were able to hack into the San Bernadino shooter’s iPhone without Apple’s help. But that’s not to say the public debates were a waste of time – it was an opportunity for everyone to think clearly about where they stand on matters of privacy and national security. These issues aren’t going away any time soon, so it’s imperative that we take the discussions seriously. A recent survey by the Pew Research Centre found that the majority of Americans sided with the FBI and believe that Apple should have complied with its demands. I find this highly concerning because it shows how easily our collective privacy could be eroded in the name of national security, and also how little most people seem to understand the encryption technologies which protect us all.
As the UN high commissioner for human rights explained recently, encryption is vital to freedom of expression and opinion, and without it, lives may be endangered. Currently, the only way to communicate securely online is to encrypt everything, so that even if your data were to be accessed by someone else, it would remain private. But any process that weakens the mathematical models used to encrypt data will make the whole system less secure, because it will also weaken the protection. In the Apple case, the FBI suggested that it could manipulate security in such a way that only it could take advantage of that subversion, but this is wrong. This is why Apple talked of the San Bernadino case setting a dangerous precedent. While it is possible to create an entirely new operating system which undermines the iPhone security features, there is no way to guarantee that this could not one day be used by someone other than the FBI. There is no way to determine when an attacker could discover a vulnerability, and once accessed, exploit it to harm anyone using that connected device, service or system.  The same vulnerabilities used by intelligence agencies to spy on global citizens can also be used by criminals to steal your passwords. We either enable spying – by either governments or hackers – or we defend against it. Backdoors will be exploited by anyone, not just the US Government.
Just like the Snooper’s Charter proposals here in the UK, these demands also force tech companies to make a difficult ethical decision. How can you tell your customers that your products are secure, but also knowingly compromise that security by building backdoors, weakening encryption and storing personal data on a huge scale? Complying with this kind of warrant equates to a catastrophic invasion of customers’ privacy, and has historically required tech companies to collude with the Government and then essentially lie about it to their customers by not disclosing it to them.
The Snowden leaks revealed how the National Security Agency in the United States convinced Microsoft to make changes to security on its Skype program to make it easier for the NSA to eavesdrop on conversations. We also know from the Snowden leaks that the NSA subverted a government standards process to be able to break encryption more easily.  Leaked documents revealed that the agency planted vulnerabilities in a cryptographic standard adopted in 2006 – effectively inserting a backdoor by writing a flaw into a random-number generator which made it easier to unscramble numbers generated by that algorithm and crack technologies using the specification.
These kind of scandals don’t just damage the products and technologies in question, but threaten to damage trust in the Internet entirely.  Internet governance was historically left largely to the United States because most people assumed that they were focussed on ensuring the security of the Internet, rather than using it as a means of surveillance. The Snowden revelations quashed that belief, and the system is now in turmoil. Some of the potential applications of the Internet that would benefit citizens and entrepreneurs have already been stymied by unresolved trust issues. E-Voting has stalled and migration to the cloud is suffering.
For the Internet to continue to grow and flourish, we need to re-establish the foundation for trust, and convince users that the systems they use online are not being used as a means to spy on them. This is no doubt why Apple is planning to hand over iCloud encryption key management to its users.  Going a step further, advances in pairing-based cryptography will soon allow a private key to be split into several different parts, eliminating the single point of failure that currently exists.  This means that governments wanting to access that key for surveillance purposes would have to fight across multiple different legal jurisdictions in order to gain access.  Even better, individual organisations may soon be able to choose how their root key would be split, empowering them to choose geographies which they feel are least likely to allow Government access.  These kind of changes put power back into the hands of the individual and give users valuable new tools in the fight to keep our data secure.
Although the FBI found a way to hack into the iPhone and dropped its court case against Apple, the issue as a whole is not over. There are no winners here, and a long battle over our collective privacy lies ahead. We all own the Internet, and we need to fix it together.
Find out more about Brian and MIRACL at their website – www.miracl.com
 

FacebookTweetLinkedIn
Tags: backdoorsCIAcollective privacyCompromisedatadata retentionEncryptionFBIGovernmentHuman rightsiphonemaster keyMIRACLnational securitypersonal dataprivacysan bernandinosecuresecuritysnooper's charterUNUS government
ShareTweetShare
Previous Post

Nuix: Cybersecurity Industry “Fighting the Wrong Battle for 20 Years"

Next Post

People still sharing data willy-nilly, Kaspersky finds

Recent News

security

What Is Observability, And Why Is It Crucial To Your Business?

March 21, 2023
Organisational Cybersecurity.jpg

How Emerging Trends in Virtual Reality Impact Cybersecurity

March 21, 2023
Nominations are Open for 2023’s European Cybersecurity Blogger Awards

Nominations are Open for 2023’s European Cybersecurity Blogger Awards

March 20, 2023
TikTok to be banned from UK Government Phones

TikTok to be banned from UK Government Phones

March 17, 2023

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2019 IT Security Guru - Website Managed by Calm Logic

  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Events
    • Most Inspiring Women in Cyber 2022
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2019 IT Security Guru - Website Managed by Calm Logic

This site uses functional cookies and external scripts to improve your experience.

Privacy settings

Privacy Settings / PENDING

This site uses functional cookies and external scripts to improve your experience. Which cookies and scripts are used and how they impact your visit is specified on the left. You may change your settings at any time. Your choices will not impact your visit.

NOTE: These settings will only apply to the browser and device you are currently using.

GDPR Compliance

Powered by Cookie Information