Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Privacy

US Could Force Firms to Help Break Encryption, Under New Bill

Washington – Two key US lawmakers Wednesday unveiled legislation to require technology firms to help law enforcement unlock encrypted devices — prompting a fierce outcry from the industry and privacy activists.

Washington – Two key US lawmakers Wednesday unveiled legislation to require technology firms to help law enforcement unlock encrypted devices — prompting a fierce outcry from the industry and privacy activists.

The bill released by Senators Richard Burr and Dianne Feinstein of the Senate Intelligence Committee comes in the wake of a heated legal battle pitting the FBI against Apple as part of an investigation into last year’s San Bernardino attacks.

“No entity or individual is above the law,” said Feinstein, the top Democrat on the committee chaired by Republican Burr.

“Today, terrorists and criminals are increasingly using encryption to foil law enforcement efforts, even in the face of a court order. We need strong encryption to protect personal data, but we also need to know when terrorists are plotting to kill Americans.”

The lawmakers in a joint statement said the proposal was a “discussion draft” and that they would “solicit input from the public and key stakeholders before formally introducing the bill.”

“I am hopeful that this draft will start a meaningful and inclusive debate on the role of encryption and its place within the rule of law,” Burr said. “Based on initial feedback, I am confident that the discussion has begun.”

The use of strong encryption in applications and smartphones, with they keys only available to users, has raised concerns in law enforcement that criminals and others may operate in secrecy, with investigators unable to gain access to data even with a court order.

Legislation similar to the Senate proposal is also being considered in other countries, notably Britain and France, amid concerns that attackers have been using encryption to avoid detection.

Advertisement. Scroll to continue reading.

But the Senate draft, which was leaked to media earlier this week, sparked intense criticism both from the technology industry and digital rights activities, claiming it would effectively create a “back door” for law enforcement which could be exploited by hackers and other governments.

Kevin Bankston of the New America Foundation’s Open Technology Institute said the bill would require “every tech vendor in America to use either backdoored encryption or no encryption at all, even though practically every security expert in the country would tell you that means laying down our arms in the constant fight to secure or data against thieves, hackers, and spies.”

Daniel Castro of the Information Technology & Innovation Foundation, a Washington think tank, said the bill “sets up a legal paradox that would further muddy the waters about how and when the government can compel the private sector to assist in gaining access to private information.”

Gary Shapiro of the Consumer Technology Association, a trade group representing hundreds of technology firms, called the measure an “overreaction” to fears on encryption.

“There is no consensus in the intelligence community that a requirement to force manufacturers to open encryption is the correct policy,” Shapiro said in a statement.

The US government last month withdrew its request to force Apple to help unlock an iPhone used by one of the San Bernardino shooters, saying the FBI had found another means to access the data. But several cases are pending against Apple and other firms.

Last week, Facebook-owned WhatsApp said it had implemented end-to-end encryption for its billion users, so that no other party can read the messages.

Written By

AFP 2023

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

More People On The Move

Expert Insights

Related Content

Artificial Intelligence

Two of humanity’s greatest drivers, greed and curiosity, will push AI development forward. Our only hope is that we can control it.

Cybercrime

Daniel Kelley was just 18 years old when he was arrested and charged on thirty counts – most infamously for the 2015 hack of...

Cybercrime

No one combatting cybercrime knows everything, but everyone in the battle has some intelligence to contribute to the larger knowledge base.

Cybercrime

The FBI dismantled the network of the prolific Hive ransomware gang and seized infrastructure in Los Angeles that was used for the operation.

Cybersecurity Funding

Los Gatos, Calif-based data protection and privacy firm Titaniam has raised $6 million seed funding from Refinery Ventures, with participation from Fusion Fund, Shasta...

Ransomware

The Hive ransomware website has been seized as part of an operation that involved law enforcement in 10 countries.

Privacy

Employees of Chinese tech giant ByteDance improperly accessed data from social media platform TikTok to track journalists in a bid to identify the source...

Privacy

Many in the United States see TikTok, the highly popular video-sharing app owned by Beijing-based ByteDance, as a threat to national security.The following is...