Posts

Showing posts with the label Backdoor

Collateral damage through the back door: there is no such thing as a bit of encryption

At the end of 2020, the European Council officially decided to support a project that would enable security authorities to read encrypted data. "Security through encryption and security despite encryption" - that is the official motto. Yet the text of the so-called European Council resolution, number 12863/20, is very vague. Messenger services are in particular focus, as they are suspected of being frequently used by criminals. For investigative authorities, this would fulfill a long-held desire to tap into private encrypted communications and read them. However, other data services are not explicitly excluded. This is precisely the issue at hand, because it makes a difference whether a communication channel is encrypted end-to-end or whether data is encrypted on cloud storage, for example. Regardless of the fact that in the latter scenario it would be negligent anyway to entrust this service to a cloud provider, because companies should always organize their encryption auton...