Stung by revelations of ubiquitous surveillance and compromised software, the internet’s engineers and programmers ponder how to fight back
SECURITY guards (at least the good ones) are paid to be paranoid. Computer-security researchers are the same. Many had long suspected that governments use the internet not only to keep tabs on particular targets, but also to snoop on entire populations. But suspicions are not facts. So when newspapers began publishing documents leaked by Edward Snowden, once employed as a contractor by America’s National Security Agency (NSA), the world’s most munificently funded electronic spy agency, those researchers sat up.
They were especially incensed by leaks published in September by the Guardian and the New York Times, which suggested that American spooks (with help from their British counterparts) had been working quietly for years to subvert and undermine the cryptographic software and standards which make secure communication over the internet possible. “At that point”, says Matthew Green, a cryptographer at Johns Hopkins University, “people started to get really upset.”
On November 6th a meeting in Vancouver of the Internet Engineering Task Force (IETF), an organisation which brings together the scientists, technicians and programmers who built the internet in the first place and whose behind-the-scenes efforts keep it running, debated what to do about all this. A strong streak of West Coast libertarianism still runs through the IETF, and the tone was mostly hostile to the idea of omnipresent surveillance. Some of its members were involved in creating the parts of the internet that spooks are now exploiting. “I think we should treat this as an attack,” said Stephen Farrell, a computer scientist from Trinity College, Dublin, in his presentation to the delegates. Discussion then moved on to what should be done to thwart it.
We have the technology
As a sort of council of elders for the internet, the IETF has plenty of soft power. But it has no formal authority. Because its standards must be acceptable to users and engineers all over the world, it works through a slow process of consensus-building. New standards, guidelines and advice take months or years to produce.
Others, equally offended by the intelligence agencies’ activities, prefer not to wait, and are simply getting on with the job of trying to restore confidence in online security. As Bruce Schneier, a leading cryptographer, told the conference, it seems spies cannot actually break most cryptographic codes. Instead they try to work around them. One way is to subvert the standards and software which implement cryptography. That is possible because, besides trying to defeat the cryptographic efforts of others, the NSA also helps produce ciphers for Americans to use. Those same cryptographic standards are then employed all over the internet.
Researchers have therefore been warning users against employing anything that might have been tampered with. RSA Security, a big maker of encryption software, has advised its customers to stop using a random-number generator widely believed to have been fiddled with by the spooks to make its output predictable (random numbers are a crucial component of any cryptographic scheme, but are notoriously hard to produce on a deterministic machine such as a computer). And a group of Brazilian mathematicians has published a new set of codes for use with elliptic-curve cryptography, a novel scrambling technique that has been championed by the NSA. Anyone worried by the provenance of NSA-supplied curves is free to use these new ones instead.
Even America’s government is getting in on the act. The credibility of its National Institute of Standards and Technology, which sets American cryptographic standards with the help of the NSA, has been dented by Mr Snowden’s revelations.
Go deeper with Bing News on:
Internet security
- Experts withdraw from Internet security conferenceon January 7, 2021 at 4:00 pm
WASHINGTON — At least eight researchers or policy experts have withdrawn from an Internet security conference after the sponsor reportedly used flawed encryption technology deliberately in ...
- The best antivirus software 2021on January 4, 2021 at 9:21 am
It's heartening to know that antivirus providers are out there fighting the good fight - constantly updating their internet security software packages to protect against ever-increasing threats to ...
- Internet Security Market Share 2021 Growth by Top Companies, Future Trends, Growth Factor, Types and Application and Forecast to 2024on January 4, 2021 at 5:10 am
Jan 04, 2021 (The Expresswire) -- “Internet Security Market” is analysed by product types, applications and key market players for market size, sales (consumption), gross margin and revenue.
- Business Internet Securityon December 23, 2020 at 3:59 pm
Small business owners are relieved that the Brexit deal has finally been agreed, as it means certainty going forward. Although … The Prospect union, recognising the plight of the 3m self-employed ...
- Internet Security Market Share, Trends, Opportunities, Projection, Revenue, Analysis Forecast To 2025on December 22, 2020 at 7:55 pm
Internet security can be understood as the all-inclusive protection of a system, which also includes browser security and security of the networks. At a fundamental level, this security is also ...
Go deeper with Google Headlines on:
Internet security
Go deeper with Bing News on:
Computer security
- Orca Security public cloud security report reveals how most large cloud breaches happenon January 14, 2021 at 3:05 am
Graham Cluley Security News is sponsored this week by the folks at Orca Security. Thanks to the great team there for their support! You’re probably familiar with the shared responsibility model.
- Global Computer Security for Customer Market 2020 Research Study with Trends and Opportunities to 2025 - Impact of COVID-19on January 6, 2021 at 3:35 am
Global Computer Security for Customer Market Growth (Status and Outlook) 2020-2025 introduced by MarketandResearch.biz offers exclusive research & analysis on the market that gives analysis on market ...
- As Comcast drops one computer security plan, what – if anything – should you replace it with?on January 3, 2021 at 1:18 pm
Comcast is rolling out free home security software for Xfinity subscribers with xFi gateways and dropping Norton's bundle. What does it mean for you?
- Computer Security For Business Market in the post Covid-19 paradigm, Global Outlook by 2021-2030on December 30, 2020 at 11:19 pm
Pune, Maharashtra, December 31 2020 (Wiredrelease) Market.Biz –:Impact of Covid-19 on the Computer Security For Business market: [Covid-19 is an unforeseen and unprecedented situation that has ...
- The Future of Computer Security for Customer Market: In-Depth Analysis & Global Outlook by 2021-2030on December 30, 2020 at 8:48 pm
Pune, Maharashtra, December 31 2020 (Wiredrelease) Market.Biz –:Impact of Covid-19 on the Computer Security for Customer market: [Covid-19 is an unforeseen and unprecedented situation that has ...