Posts

Showing posts with the label Encryption

Total surveillance through the back door: Apple's fatal fall from grace

Apple announces a kind of total surveillance for child protection with CSAM scanning, setting a fatal precedent.  "It's an absolutely appalling idea because it will lead to distributed mass surveillance of our phones and laptops," comments security luminary Ross Anderson on Apple's latest foray into "security." Cryptography professor Matthew Green warns of a dam breaking. There's really nothing to add to that. This is not about Apple searching for child porn on its servers and reporting it to the police. That's what all service providers like Google, Microsoft or Facebook do. It's about the fact that Apple now even wants to search for these images on the iPhones of its customers. Special search programs run secretly in the background on the devices without the owner's knowledge. Constantly and without any particular reason, for everyone. This is new. And it's frightening. The IT group, of all people, which likes to adorn itself with the i...

WhatsApp: This is how Facebook wants to circumvent message encryption

Facebook has assembled a team of experts to investigate the encryption of WhatsApp messages. The goal is likely to be the collection of data for personalized advertising. Facebook has hired a number of experts to look into the encryption of WhatsApp messages. Basically, only the chat partners can decrypt the corresponding messages with the app. Not even WhatsApp itself has this option. So the question arises as to how Facebook intends to obtain usable data from this. According to a report from Android Authority , the keyword is "homomorphic encryption". This would be a way to analyze data without decrypting it. However, it is still unclear how this will work exactly.  Facebook is looking for new ways to collect data What should be pretty clear, however, is the purpose of the whole action. Facebook wants to collect even more data about its users in order to be able to serve personalized ads. Unsurprisingly, Facebook has denied this intention. The issue comes at a time when Fac...

Collateral damage through the back door: there is no such thing as a bit of encryption

At the end of 2020, the European Council officially decided to support a project that would enable security authorities to read encrypted data. "Security through encryption and security despite encryption" - that is the official motto. Yet the text of the so-called European Council resolution, number 12863/20, is very vague. Messenger services are in particular focus, as they are suspected of being frequently used by criminals. For investigative authorities, this would fulfill a long-held desire to tap into private encrypted communications and read them. However, other data services are not explicitly excluded. This is precisely the issue at hand, because it makes a difference whether a communication channel is encrypted end-to-end or whether data is encrypted on cloud storage, for example. Regardless of the fact that in the latter scenario it would be negligent anyway to entrust this service to a cloud provider, because companies should always organize their encryption auton...