Feds Trying To Get Master Encryption Keys From Tech Companies

from the of-course-they-are dept

This is hardly surprising, but Declan McCullagh is reporting that the feds have been trying to get various tech companies to hand over their master encryption keys so that the NSA and FBI can decrypt any of the messages they scoop up. So far the tech companies have been resisting:

“The government is definitely demanding SSL keys from providers,” said one person who has responded to government attempts to obtain encryption keys. The source spoke with CNET on condition of anonymity.

The person said that large Internet companies have resisted the requests on the grounds that they go beyond what the law permits, but voiced concern that smaller companies without well-staffed legal departments might be less willing to put up a fight. “I believe the government is beating up on the little guys,” the person said. “The government’s view is that anything we can think of, we can compel you to do.”

It’s unclear from the article if any companies have given in and provided the keys, but it sounds like at least most of the big ones are fighting it. Microsoft and Google both directly denied that they would hand over such a master key. Lots of other companies didn’t respond to Declan’s questions. Of course, it’s no surprise that the government would ask. They’ve been asking for access and backdoors to just about everything.

If they can’t convince the companies that this is legal and required, you can fully expect that a law will be proposed shortly which will more or less require companies to hand over such keys.

“The requests are coming because the Internet is very rapidly changing to an encrypted model,” a former Justice Department official said. “SSL has really impacted the capability of U.S. law enforcement. They’re now going to the ultimate application layer provider.”

Once again, perhaps it’s time to think about moving away from a situation in which all our “cloud” data is stored in a few centralized spots. You can still get the benefits of a cloud, even if you control the data yourself — if only companies would open up and allow users to point their services at data stored elsewhere.

Filed Under: , , , , , , ,

Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “Feds Trying To Get Master Encryption Keys From Tech Companies”

Subscribe: RSS Leave a comment
The Real Michael says:

Re: Re:

They’re not simply out of control, they’ve gone stark raving mad. “Give us your encryption keys because we said so.” How about no.

Wonder what will happen with all those Kickstarter projects and whatnot that are attempting to encrypt data/communication. If they don’t cave to the government’s (UNCONSTITUTIONAL) demands, the latter will likely falsely accuse them of aiding the enemy, because they’re lunatics.

Anonymous Coward says:

so, surely the answer then is for all the companies concerned to have a united front and help each other, isn’t it? look at what the entertainment industries achieve, just because they can draw on resources from near and far. it’s no good the ‘big boys’ being able to resist if the ‘little guys’ cant. all that will lead to is courts using the defeat of the little guys as precedent to get the ‘big guys’ to confirm. dont take a surgeon to know the way to go on this, does it?

FM HIlton (profile) says:

Not that we'd care

Like just open up all the channels and have done with it. Of course the Internet is a tameable beast, so they have to have all the keys to it.

If they get them, I’m off forever. If you can’t be secure at all with any of it, why bother?

The SSL keys are the only thing stopping the NSA from having real-time spying on-line, and it’s only a matter of time before these companies give in because they’re gutless cowards, just like everyone who doesn’t care.

It might not be surprising to some people but it is highly disturbing to me, and I’m pretty much convinced that the end is near for that ‘wild west’ synergy that used to be so true on the Internet.

It’ll be owned and controlled by the corporate masters and watched every second by the NSA. Nothing will be private, nothing will be secure.

We’re half-way there now. I can see the writing all over the wall-ten feet high.

lfroen (profile) says:

Re: Not that we'd care

Nothing prevent you from storing your data at your own computer, you know.
Go buy some tiny box with linux inside, connect usb disk, turn encryption on. That’s it. Want to communicate with your box over internet – few more checkboxes.

Your government want an ability to wiretap communications. What’s new about it? Do you know that you phone has never been encrypted?

NSA_Is_The_Threat says:

Why is the net pursuing encryption?

The trend towards encryption on the net is driven by the fact that it makes us safer. We can trust what we read, who we are talking to, that our private matters, like credit cards and youthful indiscretions, remain so.

The monetary rewards for stealing our private actions is large. Most elected now have used data mining and demographic analysis to get elected – they think they need to keep lying and stealing to stay in office.

The nation needs ambiguity and privacy. It need transparancy, so we can see what our tax dollar buys us. The consent of the justly governed is an informed consent.

vastrightwing (profile) says:

Plausible deniability

I don’t believe them: I trust everything that Google, Apple, Yahoo and Microsoft say the same way I trust everything the government says.

There is an encryption technology called plausible deniability: dual encrypted channels with double keys. When the government demands the keys, you give them one set of keys to placate them so you don’t end up in jail. I won’t bore you with the details, but check out True Crypt.

I never liked the idea of storing anything of mine on rack servers (AKA the cloud) owned by anyone other than me. All the B.S. about we protect you is utter nonsense. I’m going back to type writers, in person face to face communications, and when I do use skynet, I’ll encrypt my messages on top of the SSL layer. Then I’ll use TOR because I don’t even want anyone knowing where I’m sending messages to in the first place. If they want to track me, they can use old fashioned detective work.

Anonymous Coward says:

I agree ms would probably do it in a heartbeat. possibly google too. I don’t trust anything on the internet. never have/will.

ms tried to get google censored. I think they actually sued them or at least tried to. probably so they could say “look bing works better than google”. yeah now that it’s crippled MICRO-DICK

John Fenderson (profile) says:

Public Key Encryption 101

The web of trust model would help a lot.

What would help even more is if there was some way to get people to take encryption seriously, and not just as a checkbox or prepending https to a url.

The notion of “trust” is absolutely core to the security of public key encryption. You need to determine whether a key you are using was actually issued by who you think it was issued by.

We now know that the default way this is “ensured”, that it was vouched for by a CA such as Verisign, Microsoft, etc., is meaningless in terms of being able to trust the key. People have to start taking a more active role in verifying the keys they use.

Chris Brand says:

A new law ?

“you can fully expect that a law will be proposed shortly which will more or less require companies to hand over such keys”. I doubt it. Too difficult to sneak something like that by right now. They’ll just go to the FISA court and get it to interpret some existing law in a way that allows them to demand what they want.

Mark Atwood (profile) says:

Why do they even need this?

The *only* use case for the government to have the SSL/TLS master private keys is so they can eavesdrop on the resulting communication without even bothering with a warrant or subpoena.

Why would the Obama Justice department want to spy on your Google Searches in such a way that they don’t want to send a subpoena to Google? Hmm?!

The only question of real import is: WHY HAVN’T WE HUNG THESE PEOPLE YET?

vastrightwing (profile) says:

The gate keepers

After further consideration, I come to the conclusion that all the mentioned companies will gladly hand over the keys. I repeat, they will gladly hand over the keys because the government has stuff they want! Data! Yes, Quid pro quo. I’m sure that since the NSA is acting as the gate keeper of all this meta data, they are liberally sharing stats and other information with their partners. Of course they’re lying to all their partners about it telling each one that they aren’t sharing their data with the competition.

Imagine the NSA telling Microsoft there is an exploit in the OS long before anyone is publically aware of it. The NSA will tell them about it and ask them not to patch it yet. This way, the NSA can exploit it themselves. Microsoft can start fixing it so when the vulnerability goes public, Microsoft can have a patch ready to go. Ditto with all the viruses. I wonder how many viruses are military in nature?

I imagine there is a whole lot of information sharing going on we have not learned about yet. The NSA, being the gate keepers keeping big tech in check.

Leave a Reply to Alasdair Fox Cancel reply

Your email address will not be published. Required fields are marked *

Have a Techdirt Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop »

Follow Techdirt

Techdirt Daily Newsletter

Techdirt Deals
Techdirt Insider Discord
The latest chatter on the Techdirt Insider Discord channel...