• UK Online Safety Bill Set to Weaken Encryption and Put UK Internet Users At Risk

    Home » Forums » Cyber Security Information and Advisories » Code Red – Security/Privacy advisories » UK Online Safety Bill Set to Weaken Encryption and Put UK Internet Users At Risk

    Author
    Topic
    #2573854

    https://bills.parliament.uk/bills/3137

    https://bills.parliament.uk/bills/3137/stages/17765

    UK wants a backdoor into encrypted messages, data…

    https://www.internetsociety.org/blog/2022/01/uk-online-safety-bill-set-to-weaken-encryption-and-put-uk-internet-users-at-risk/

    ..Despite claims it seeks to protect users online, the recent draft of the Bill threatens to drive strong encryption from the market and place UK Internet users at greater risk than ever before.

    The draft Online Safety Bill will force service providers to weaken or remove encryption to meet new content identification and removal requirements…

    4 users thanked author for this post.
    Viewing 3 reply threads
    Author
    Replies
    • #2574689

      Apple says it will remove services such as FaceTime and iMessage from the UK rather than weaken security if new proposals are made law and acted upon.

      The government is seeking to update the Investigatory Powers Act (IPA) 2016.

      It wants messaging services to clear security features with the Home Office before releasing them to customers.

      The act lets the Home Office demand security features are disabled, without telling the public. Under the update, this would have to be immediate…

      The government is seeking to update the Investigatory Powers Act (IPA) 2016.

      It wants messaging services to clear security features with the Home Office before releasing them to customers.

      The act lets the Home Office demand security features are disabled, without telling the public. Under the update, this would have to be immediate.

      Apple says:

      It would not make changes to security features specifically for one country that would weaken a product for all users.

      Some changes would require issuing a software update so could not be made secretly
      The proposals “constitute a serious and direct threat to data security and information privacy” that would affect people outside the UK.

      3 users thanked author for this post.
    • #2574700

      Apple together with Signal and Whatsapp are 100% right IMO
      They should all hit the UK Govt with an ‘App fee’ to undo their security features, should this IPA 2016 ammendment be approved and introduced.

      Windows - commercial by definition and now function...
      1 user thanked author for this post.
      • #2574709

        The potential new MITM is the UK Home Office, I’m safe in the knowledge that their security is better than apple’s /s

        Windows - commercial by definition and now function...
        1 user thanked author for this post.
    • #2574831

      ..Despite claims it seeks to protect users online, the recent draft of the Bill threatens to drive strong encryption from the market and place UK Internet users at greater risk than ever before. The draft Online Safety Bill will force service providers to weaken or remove encryption to meet new content identification and removal requirements…

      Mind you, the wish to weaken encryption is not only in England, but in other countries as well.  The data bunkers in Utah are not there to store groceries. In the EU there are, as always, best-knowing-politicians who think they can stop the crooks with this weakening of the basics of the internet.

      * _ ... _ *
      3 users thanked author for this post.
      • #2574838

        I remember the days when Microsoft denied usage of IE, outside US, due to 128bit encryption.

        1 user thanked author for this post.
        • #2574895

          yes, those were the days; most of us so innocent and believing in the future developement.

          * _ ... _ *
      • #2583990

        The data bunkers in Utah are not there to store groceries.

        Well I thought they use SNDL. Right now, they simply collect data and do not know, what are containing.

        Dell Latitude 3420, Intel Core i7 @ 2.8 GHz, 16GB RAM, W10 22H2 Enterprise

        HAL3000, AMD Athlon 200GE @ 3,4 GHz, 8GB RAM, Fedora 29

        PRUSA i3 MK3S+

    • #2583293

      UK will block security fixes fixing vulnerabilities that are being exploited by security services.

      ..

      Objective 4 of the proposed changes adds another layer to the current regulatory landscape by including an obligation for companies to notify the government before introducing any technical changes to their systems.

      Device manufacturers would likely also have to notify the government before making available important security updates that fix known vulnerabilities and keep devices secure. Accordingly, the Secretary of State, upon receiving such an advance notice, could now request operators to, for instance, abstain from patching security gaps to allow the government to maintain access for surveillance purposes…

    Viewing 3 reply threads
    Reply To: UK Online Safety Bill Set to Weaken Encryption and Put UK Internet Users At Risk

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: