It is said that the one thing one can learn from history is that we don’t learn from history. The clipper chip is an example of this, and it shows again today.
It is April 16, 1993. The White House announces the ‚Clipper chip‘, officially known as the MYK-78. It was meant for use in secure communication devices like phones, protecting calls from interception by encrypting them.
Each Clipper chip came with a pre-baked, unique secret key, but the chip also had one extra ‚feature‘: the cryptographic key was not just known to the recipient, but also to law enforcement agencies like the CIA and FBI. In a slight nod to privacy, the ‚backdoor key‘ was to be split in two and shared between two federal agencies, blocking any single party from use.
The tech world protested: weakening encryption by building in a back door was a bad idea. Only one device was ever produced, by AT&T Bell. It took just one year for a major design flaw to break the encryption, putting a final nail in the coffin of the project.
It is May 24, 2019. The German ‚Der Spiegel‘ reports that the German minister of interior afairs is working on a project that will force communication apps to break their encryption and give surveillance agencies access to their content.
Today, June 11, together with over 100 other organizations, Nextcloud signed a public letter against this plan-in-development. This was a bad idea in 1993, it is a bad idea today.
Five issues with a crypto backdoor
The criticism, as explained in the letter, covers 5 main things.
First, it goes against over 20 years of successful crypto-related policy in Germany, making Germany one the most secure countries in the cyber economy.
Second, more technically speaking, the vulnerability that has to be built into messenger software can of course be used by anyone, not just the government. This means access to the data by criminals, but also, of course, employees of the companies behind the apps. And while the government has said to block any service which keeps using encryption, there are many other ways of encrypting data. The data of ’normal‘ users won’t ben encrypted anymore, but criminals and terrorists of course are very motivated to keep their communication safe.
The third point extends the last element of the second: the supposed benefits for law enforcement are dubious at best. There is no evidence of increased difficulty of surveillance, rather an increased use of it. Mostly, surveillance is done with ‚Trojan horses‘, apps which infect the device of a target and, before data is encrypted, share it with law enforcement. This targeted approach works well and represents a more balanced approach to law enforcement vs privacy.
Fourth, Germany does not operate in a vacuum. The international community watches and this move will be used by authoritarian states to justify their mass surveillance. The credibility of Germany as an international proponent of freedom, leader of the free world perhaps, will be tarnished.
Last, but not least, this will have big consequences for the industry in Germany, putting it at a serious disadvantage. When people know that their digital communication in Germany isn’t entirely safe, financial services, healthcare and other sectors will be negatively impacted. The letter notes that in 2016 and 2017, the total costs of sabotage and cyber spying was over 43 billion euro, and with a weakened state of encryption the costs of breaches will go up. Innovation will suffer, as technology theft becomes easier and Germany won’t be as good a place to start a business or do R&D anymore.
Nextcloud ist die erste Cloud-Plattform, die mit dem Umweltzeichen „Blauer Engel“ ausgezeichnet wurde und damit beweist, dass eine digital souveräne und grüne IT möglich ist.
Wir stellen Nextcloud Talk „Munich“ vor - eine digital souveräne Open-Source-Kommunikationsplattform für hybride Teams, die eine starke Antwort auf die Clouds von Big Tech bietet. Jetzt noch resilienter, leistungsfähiger und einfacher in der Anwendung. Erfahren Sie mehr.
Willkommen bei Nextcloud Hub 10. Die neueste Version der Plattform bietet eine besserte Leistung für alle Apps, besser Integration Plattform und Dutzende neuer Funktionen, die Ihnen den Alltag erleichtern werden.
Unternehmen, ob klein oder groß, brauchen eine Möglichkeit, die Ausfallsicherheit und digitale Souveränität ihrer Abläufe zu gewährleisten - eine Open-Source-Alternative zu Teams, die die Privatsphäre respektiert. Und heute stellen wir diese Lösung vor - Nextcloud Talk.
Bechtle und Nextcloud kündigen heute eine vollständig verwaltete Kollaborationsplattform für den öffentlichen Sektor an, die keiner Ausschreibung bedarf und sofort bereitgestellt werden kann.
Our mission is to help individuals, businesses and organizations achieve digital sovereignty and regain control over their data. Nextcloud Hub 5 marks a massive step forward towards achieving this mission, putting the power of AI into your hands – in a way that keeps you in control. New release, new possibilities Hub 5 builds on […]
Passionate about data privacy and Nextcloud? We invite you speak at the Nextcloud Community Conference to share your experience, knowledge and news with the community!
Nextcloud announces new partnership with Thinkfree Office, a self-hosted office suite developed in South Korea, which is known for its ease of use. This collaboration is all about giving you more options, greater control, and a better user experience.
Wir speichern einige Cookies, um Besucher zu zählen und die Nutzung der Website zu erleichtern. Diese verlassen unseren Server nicht und dienen nicht der Verfolgung Ihrer online-Aktivitäten.
Weitere Informationen hierzu finden Sie in unserer Datenschutzrichtlinie. Anpassen
Statistik-Cookies sammeln anonym Informationen und helfen uns zu verstehen, wie unsere Besucher unsere Website nutzen. Wir verwenden cloud-gehostetes Matomo
Dienst:Matomo
Cookie-Beschreibung:
_pk_ses*: Zählt den ersten Besuch des Benutzers
_pk_id*: Hilft, die Besuche nicht doppelt zu zählen.
mtm_cookie_consent: Erinnert daran, dass der Nutzer seine Zustimmung zur Speicherung und Verwendung von Cookies gegeben hat.
Cookie-Ablauf:_pk_ses*: 30 Minuten
_pk_id*: 28 Tage
mtm_cookie_consent: 30 Tage
Comments