Live data from Hacker News

European Union dedicated questionnaire on the Encryption of Data

blog.lukaszolejnik.com

91–100 of 113 posts

Re: European Union dedicated questionnaire on the Encryption of Data

#91
post #78
post #71

Earlier quoted context omitted.

I guess GP was referring to ZITIS, not BSI. BSI's job generally is ensuring IT security, not breaking it. Even the weirder jobs they're tasked with, such as certifying backdoor software for LEAs, it's not about ensuring its operation as a backdoor, but that it only does the designated job (and in particular doesn't bring additional capabilities that are outside their charter)

Yes, I was referring to ZITIS. > BSI's job generally is ensuring IT security, not breaking it. Unfortunately that's also not true. The role of the BSI is very mixed and they have a role as both being offensive and defensive. Which is one of the problems. They're not trustworthy.

So which department shown on https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/BSI/Orga... has an offensive role?

The BND/BSI split as implemented in Germany is relatively unique precisely to separate offensive and defensive concerns. The biggest issue IMHO is that they both report to the same federal office.

Re: European Union dedicated questionnaire on the Encryption of Data

#92
I've collated the answers to some of the questions:

* How often do you encounter encryption? The most common answer is 'often'. Germany does not collect this statistic. Czech Republic and Hungary: 'rarely', Latvia has both 'often' and 'almost always' in bold, UK 'almost always'.

* Online encryption: most common one is e-comms (everywhere but Italy), followed by TOR (everywhere but Hungary and Poland). Denmark, Finland, Germany and the UK reported encountering all types of encryption on the form.

* Offline encryption: it's not very clear what is an encrypted device (it includes computers) and what is an encrypting application (they give disk encryption tools as examples), but all countries except Poland selected devices and all countries except Italy selected applications

* It sounds like the accused can only be compelled to disclose passwords or keys in the UK, but Italian LE would also like that very much, despite having reported that 'the current national law allows sufficiently effective securing of e-evidence when encrypted'.

* In Croatia, Latvia and Poland they consider that the current national laws don't allow effective securing of encrypted evidence. The answer to this question is not available for Czech Republic and the UK.

A few other interesting things I've noticed:

Croatia: 'There is no practical experience' regarding 'intercepting/monitoring encrypted data flow'; 'Tools for decryption are used in less complex case [...]. Foreign companies’ services were not used so far.'

Czech Republic: 'Additional intentional encryption is quite rare in most cases although encrypted mobile phones are more and more popular among members of certain organized crime groups.'

Denmark: 'The main issue with trying to decrypt encrypted data is of a technical nature. Furthermore the equipment needed to break encryption is costly and the process itself takes a lot of time.'; 'In general terms, we can inform you that commercial software is among the tools used to decrypt data'; 'Decryption typically requires large hardware resources (processing power) as the encryption offered by service providers is very strong.'

Estonia: 'The main problem is that communication or data are encrypted and if key is not available, it is not possible to decrypt them.'

Finland: 'In case of full-disk encryption, which is rare, we have to either use brute force attacks, or try to obtain the credentials some other way'; 'We do not usually use private sector companies for decryption purposes, but of course a large part of the software/hardware used are commercial products'; 'Wireless criminal intelligence gathering can be challenging, because the LE sector has limited legal rights to gather for example WIFI data'; 'Sometimes insufficient computational capacity of our password-breaking platforms make the decrypting process too lengthy'; In general they talk about C&C servers for botnets quite a lot.

Germany: Regarding intercepted encrypted comms: 'In many cases, analysis of actual communication content is not feasible.', 'A regulation to prohibit or to weaken encryption for telecommunication and digital services has to be ruled out, in order to protect privacy and business secrets.'

Hungary: it sounds like they gave the form to the wrong dept? 'Our unit is not dealing with decryption, therefore we do not have any practical experience in this field.', 'Our unit is not dealing with such techniques.'

Italy: covered in the OP

Latvia: 'LV sees as clear added value of EC3’s encryption/decryption platform; LV also highly values the availability of the Europol Platform for Experts.';

Poland: mostly covered in the OP, I'll add 'The specialised computers (GPU clasters[sic]) which can decrypt encrypted e-evidences are very expensive.'

UK: It reads like a polished PR piece, at least relative to the others. Provides non-answers. It's probably worth taking a closer look. For example to 'Under your national law, is it possible to intercept/monitor encrypted data flow to obtain decrypted data for the purposes of criminal proceeding?' they responded with 'Section 17 of the Regulation of Investigatory Powers Act 2000 prevents intercepted material from being used as evidence in legal proceedings.', which doesn't actually answer the question.

Re: European Union dedicated questionnaire on the Encryption of Data

#93
post #5

Surprisingly interesting content for the clickbaity headline: Some excerpts from a questionnaire about how law enforcement deals with encryption answered by various EU governments, with esp. Poland calling for backdoors or weakened encryption. The full answers are here: https://www.asktheeu.org/en/request/input_provided_by_ms_on_...

Poland...calling for weakened encryption and backdoors. Students are going to be so confused when they see that 4 chapters after WWII in their history books.

Poland broke codes during WWII, wants to break codes now. No changes here!

Re: European Union dedicated questionnaire on the Encryption of Data

#94
post #75

Earlier quoted context omitted.

I've heard the judge can then ask you again , and you can go back to jail if you refuse, because that's a separate offense or something.

Do you have a written citation for that, something from Out-Law.com (or equivalent), or from a qualified solicitor or barrister, which backs up the "I've heard..." up a little? Not trying to be a hard ass, but I don't think HN benefits from people spreading "legal facts" (c.f. indefinite imprisonment) with an authoritative written tone but without citing legal precedent, or a detailed analysis of the statute in quest…

I have no substantial evidence to speak of. And I thank you for knocking me off my horse, I was being hasty. Have my upvotes.

Now I checked Wikipedia about those laws, it appears France (my country) has a similar law since 2001. Bummer, I guess.

Re: European Union dedicated questionnaire on the Encryption of Data

#95
post #91
post #78

Earlier quoted context omitted.

Yes, I was referring to ZITIS. > BSI's job generally is ensuring IT security, not breaking it. Unfortunately that's also not true. The role of the BSI is very mixed and they have a role as both being offensive and defensive. Which is one of the problems. They're not trustworthy.

So which department shown on https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/BSI/Orga... has an offensive role? The BND/BSI split as implemented in Germany is relatively unique precisely to separate offensive and defensive concerns. The biggest issue IMHO is that they both report to the same federal office.

Here's some (german) background info on the role. The BSI assisted the BKA in creating a trojan, but tried to hide it from the public: https://netzpolitik.org/2015/geheime-kommunikation-bsi-progr...

Re: European Union dedicated questionnaire on the Encryption of Data

#97
post #60

I find the german answers [1] surprisingly reasonable. High Five for the final answer: > 11. Are there other issues that you would like to raise in relation to encryption and the possible approach to these issues? Please share any relevant national experience or considerations arising from your practice that need to be taken into account. > Yes. A regulation to prohibit or to weaken encryption for telecommunication a…

I come from Germany. The situation is complicated. The responsible politicians tend to make statements that are contradicting or don't make any sense. There have been multiple statements that at least could be interpreted as supportive of encryption regulation. In one occasion there was a joint statement by the french and german ministers of interior - with the slight problem that the french and german versions of th…

>Recently they created a new institution supposed to help decrypting messages.

Could you give me more info about it?

Re: European Union dedicated questionnaire on the Encryption of Data

#98

Earlier quoted context omitted.

> How do you prove yourself innocent then? You did give them the keys. Well, prosecution needs to have a legally convincing argument that indicates it is likely you have another encrypted partition you're not giving up keys to. In fact, the situation is no different from this: say you're a murder suspect and a neighbour saw you carrying several large heavy sacks into your car and you drove away. Say what really happe…

That's fine, but your argument is effectively that you are screwed no matter what. If you are truly innocent, the prosecution might claim "oh they have extra keys that they haven't given up", and there is nothing you can do to prove them wrong.

Like jbg said in another comment here, the legal system doesn't work that way, where the prosecution can claim you did stuff and you have to disprove the claim. The burden of proof is on the prosecution.

Re: European Union dedicated questionnaire on the Encryption of Data

#99
post #87

Earlier quoted context omitted.

Well, they don't matter wrt. the law. Either the prosecution is convinced you gave up all the keys (you win), or they believe you gave them a key that was just a distraction and they throw you in jail unless you give them the other key (you lose).

In most jurisdictions, the prosecution being _convinced_ that you are guilty isn't enough to throw you in jail -- there's still the small issue of proving their case in front of a judge.

Thanks for pointing this out. I was thinking "judge or jury" but wrote "prosecution" in my comment above.

Re: European Union dedicated questionnaire on the Encryption of Data

#100

Earlier quoted context omitted.

That's fine, but your argument is effectively that you are screwed no matter what. If you are truly innocent, the prosecution might claim "oh they have extra keys that they haven't given up", and there is nothing you can do to prove them wrong.

Like jbg said in another comment here, the legal system doesn't work that way, where the prosecution can claim you did stuff and you have to disprove the claim. The burden of proof is on the prosecution.

So you are agreeing with me that this tactic of plausible deniability with multiple encryption keys works then?

Which is it? Does encryption allow you to hide from the law, or can innocent people just be proclaimed that they are hiding something and that they have to give up keys that don't exist?

It is one or the other, because encryption plus multiple keys makes you 'indistinguishable' from an innocent person who truly cannot give you a key that doesn't exist.

Post reply on HN