Live data from Hacker News

CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

itsecurityguru.org

1–10 of 86 posts

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#3
Wow, shows a lot of integrity closing the product instead of still keeping it up in a compromised state to comply with the warrant. We've seen some other providers here in the US even changed functionality to retain keys used in web clients of secure email at the behest of government orders.

This does mean that the UK is now on the list, along with the US, of places where no credible crypto startup is possible, though.

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#4
There are some details of the legislation in question here[1]. It allows the UK to monitor "in the interests of the economic well-being of the United Kingdom" which seems a little broad!

It would be interesting to know if this warrant targeted all users or a specific subset?

I wonder how they decide whether to issue a warrant or just break into the site in question. A warrant could imply that they are unable to attack the provider, or that they want to have a chilling effect.

[1]http://wiki.openrightsgroup.org/wiki/Regulation_of_Investiga...

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#5
post #3

Wow, shows a lot of integrity closing the product instead of still keeping it up in a compromised state to comply with the warrant. We've seen some other providers here in the US even changed functionality to retain keys used in web clients of secure email at the behest of government orders. This does mean that the UK is now on the list, along with the US, of places where no credible crypto startup is possible, thoug…

The article also mentions this company's new product where additional security is possible because decryption requires data kept only by the customer. Perhaps that is the new way to go?

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#6
post #4

There are some details of the legislation in question here[1]. It allows the UK to monitor "in the interests of the economic well-being of the United Kingdom" which seems a little broad! It would be interesting to know if this warrant targeted all users or a specific subset? I wonder how they decide whether to issue a warrant or just break into the site in question. A warrant could imply that they are unable to attac…

"In the name of the People, shut down this facility!"

Well, that sounds familiar. It seems the more governments change over the decades, the more they stay the same.

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#7
post #3

Wow, shows a lot of integrity closing the product instead of still keeping it up in a compromised state to comply with the warrant. We've seen some other providers here in the US even changed functionality to retain keys used in web clients of secure email at the behest of government orders. This does mean that the UK is now on the list, along with the US, of places where no credible crypto startup is possible, thoug…

The article also mentions this company's new product where additional security is possible because decryption requires data kept only by the customer. Perhaps that is the new way to go?

I was wondering about that, it is described as:

"where rather than hold the data, it is split in two so CertiVox has one half and the user has the other, and law enforcement would need both to access the data."

By data here, do they mean encryption key? If so then I'm not sure what splitting it in two does as you presumably have to join them together somewhere and GCHQ would presumably just attack wherever the complete key is available.

[Edit: Product details here, it appears to be Open Source: http://www.certivox.com/m-pin/]

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#8
post #7

Earlier quoted context omitted.

The article also mentions this company's new product where additional security is possible because decryption requires data kept only by the customer. Perhaps that is the new way to go?

I was wondering about that, it is described as: "where rather than hold the data, it is split in two so CertiVox has one half and the user has the other, and law enforcement would need both to access the data." By data here, do they mean encryption key? If so then I'm not sure what splitting it in two does as you presumably have to join them together somewhere and GCHQ would presumably just attack wherever the comple…

I don't know anything about the implementation, but I would assume that the idea is to avoid having the service provider be a single point where complete failure can occur. Perhaps this new system offloads that risk to the customer.

But then I get confused, what service is the service provider providing if the customer still needs to carry around half of 'the data'?

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#9
post #7

Earlier quoted context omitted.

I was wondering about that, it is described as: "where rather than hold the data, it is split in two so CertiVox has one half and the user has the other, and law enforcement would need both to access the data." By data here, do they mean encryption key? If so then I'm not sure what splitting it in two does as you presumably have to join them together somewhere and GCHQ would presumably just attack wherever the comple…

I don't know anything about the implementation, but I would assume that the idea is to avoid having the service provider be a single point where complete failure can occur. Perhaps this new system offloads that risk to the customer. But then I get confused, what service is the service provider providing if the customer still needs to carry around half of 'the data'?

Splitting it in two does not mean splitting it in half.

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#10
post #4

There are some details of the legislation in question here[1]. It allows the UK to monitor "in the interests of the economic well-being of the United Kingdom" which seems a little broad! It would be interesting to know if this warrant targeted all users or a specific subset? I wonder how they decide whether to issue a warrant or just break into the site in question. A warrant could imply that they are unable to attac…

RIPA was strongly opposed by the IT and communications community during its 'consultation' period, but was passed largely intact. It was so intrusive a proposal that even people like me who often say 'I'll write and complain' actually did write a letter.

Predictions of its misuse have been borne out, particularly as the authorized users of communication data were never enumerated or restricted. So we have the situation today where local Councils use RIPA to obtain communication data regarding individual citizens' activities.

Post reply on HN