Report: U.S. Gov't Revises Stance On 'Golden Key' Approach To Encryption

According to a report in the Washington Post, the U.S. government has "evolved" its thinking on backdoors. It's not looking for a "golden key" anymore. Instead, it's now considering requiring companies to give it remote access to the targets' devices through automatic updates to users' devices and software, making them implement special encrypted ports in hardware that gives the government access to devices, setting up a system of split-key backdoors (so like a "golden key" broken into multiple pieces), or forcing them to backup users' data when they are not paying attention.

Latest Videos FromTom's Hardware
TOPICS
Contributor

Lucian Armasu is a Contributing Writer for Tom's Hardware US. He covers software news and the issues surrounding privacy and security.

  • thor220
    It would be funny if they did do Hijacked updates. Would make windows 10 all the more unpopular.
    Reply
  • Math Geek
    the "bad guys" the government wants to monitor is already smarter than these types of back doors would help them track. a simple encrypted message emailed is transferred to a thumb drive, then opened and read on a machine that is unconnected to the web in any way. the response is typed and encrypted on this machine as well, then transferred back to the first machine to be sent in an email. at no time is this data unencrypted and available for it to be uploaded to the web by whoever is trying to get it.

    this has been employed for a very long time by the "bad guys" since the backdoors have been in place for a very long time. think about the Bin Laden raid and all the juicy bits they got from the pc's they got there. all this was new info since it was kept off the grid by simply not connecting them to the web to be hacked and read by the governments who wanted to read it. everything was sent encrypted and only opened off the grid.

    the backdoors will only allow the gov to spy on citizens who really are not a threat. i spent a number of years working in the intelligence field and can say for sure that this method has been in use since before 9/11 and after. there is no reason to think that they will all of a sudden stop doing this now ESPECIALLY if the exploit is publicly known and acknowledged. the gov already intercepts all web traffic just about world wide and can't read this encrypted data. they are hoping this backdoor will allow them to catch the data before it is encrypted and vulnerable.

    the "bad guys" are just smarter than this and it won't have any effect.
    Reply
  • Onus
    In the US, this would be a clear violation of the 4th Amendment, which requires a warrant (supported by sworn affidavit) before a search (which must be specific) can be conducted.
    For those outside the US, this is the amendment that recognizes the right of the people to be secure in their persons, papers, and effects against unreasonable search and seizure. IMHO, it is important to note that neither this amendment, nor any other, grants any rights, they recognize inherent, pre-existing rights that it was our government's chartered purpose to secure. If you're laughing, you probably should be crying.
    Reply
  • skit75
    Front door, back door or my window..... Get a warrant, even if the door or window is open. The chilling effect of some of these ideas grossly outweighs any perceived benefit.
    Reply
  • Math Geek
    16677879 said:
    In the US, this would be a clear violation of the 4th Amendment, which requires a warrant (supported by sworn affidavit) before a search (which must be specific) can be conducted.
    For those outside the US, this is the amendment that recognizes the right of the people to be secure in their persons, papers, and effects against unreasonable search and seizure. IMHO, it is important to note that neither this amendment, nor any other, grants any rights, they recognize inherent, pre-existing rights that it was our government's chartered purpose to secure. If you're laughing, you probably should be crying.

    the 4th amendment has already gone out the window with the mass info grab they have been doing and the SCOTUS has upheld the gathering. this would actually require multiple agencies to agree and put their keys together to get at a person's data. arguably less intrusive since the exploit has to be specifically activated to be used rather than the mass data the collect now "in case they need it".

    i don't like either one myself but do understand what they are trying to do. i can say that in my years working in the field in an active war zone i never once used the mass collected data for anything useful. we got all we needed from specifically targeting a person's devices and/or pc's for data. we could tap a cell phone or other device of the person we wanted to monitor. this is why they quickly went back to staying off the grid and literally passing hand written notes to pass along data before they figured out encrypted data was the way to go so long as it was read off grid.

    this literally will have no effect on day to day for the true enemies who have already been pretty smart in their info security than we want to give them credit for.
    Reply
  • dgingeri
    I say we get a full on class action lawsuit going to sue the government and force the law to make it illegal to even ASK for such things.
    Reply
  • Math Geek
    16677952 said:
    I say we get a full on class action lawsuit going to sue the government and force the law to make it illegal to even ASK for such things.

    the SCOTUS has already upheld the data collecting multiple times now. we have already lost the case and can only take steps to protect yourself as you go. keep important data offline and only connect to send the data encrypted is the only way to go. if it is connected it WILL BE READ, is pretty much the moral of the story from here on out,.
    Reply
  • xenogen
    I can verify that the authorities have been targeting our smartphones/flip phones for a long time... I had to go to the SDPD for an errand. I noticed while waiting in the lobby that a virus had entered my phone through bluetooth. It created a small message in the phone, connect to xyz virus with some bug symbol that flashed for a second. At the time Bluetooth was new tech and there had been reports of Bluetooth viruses in the news. I was going to bring it up to the staff but decided not to. This was on a flip phone, blue in color, popular for t-mobile around 2003. I now believe that virus was not from a crook hacker but from the police department itself. Without a doubt. True story. 100%
    Reply
  • stuart lynne
    If the government wants weakened security will the government provide liability coverage for malicious use.

    The dollar value for data breaches that use these back doors (or Golden Keys) could amount to billions (with a B) of dollars. Will the government be there to pay that out to 1st parties (companies that get breached) or 2nd parties (users whose data got stolen.) Or reimburse for funds lost?

    While the government has a wicked problem protecting us from terrorist attacks. They run the risk of imposing far higher burdens on us from the run of the mill criminal use of our data and theft of our funds. If they are going to weaken security they need to say who is going to pay for the increase cost of that use by criminals. And it is a number in the billions of dollars per year range.
    Reply
  • Wisecracker
    1) You guys should read and comprehend the piece in the Post; and
    2) Lucian Armasu should be flogged.
    Reply