TechRepublic : A ZDNet Tech Community

IT News Digest

Host: Sonja Thompson
Contact

Law that compels the surrender of encryption keys goes into effect in the United Kingdom

According to Ars Technica, new laws go into effect in the United Kingdom that make it a crime to refuse to decrypt almost any encrypted data that’s requested as part of a police investigation.

Individuals who refuse to comply with orders to hand over either cryptographic keys or data in decrypted form will face up to five years in prison.

Excerpt from Ars Technica:

Part 3, Section 49 of the Regulation of Investigatory Powers Act (RIPA) includes provisions for the decryption requirements, which are applied differently based on the kind of investigation underway… the five-year imprisonment penalty is reserved for cases involving anti-terrorism efforts. All other failures to comply can be met with a maximum two-year sentence.

This law is applicable only to data physically stored in the United Kingdom and does not allow the U.K. government to intercept encrypted materials in transit.

The aspect of this new legislation that has experts worried has to do with the fact that law enforcement now has the power to seize encryption keys.

Cambridge University security expert Richard Clayton said earlier last year, “The notion that international bankers would be wary of bringing master keys into the U.K. if they could be seized as part of legitimate police operations, or by a corrupt chief constable, has quite a lot of traction. With the appropriate paperwork, keys can be seized. If you’re an international banker you’ll plonk your headquarters in Zurich.”

With the increasing availability and use of strong encryption, enacting laws to force the surrender of encryption keys appears to be the easiest way out for government agencies.

Do you foresee similar laws being passed where you live?

Print/View all Posts Comments on this blog

TrueCrypt thrawts RIPA III divt4j_techrepublic@... | 10/02/07
TrueCrypt's "aleatory" defence against RIPA divt4j_techrepublic@... | 10/02/07
"Off-the-Record Messaging" defence against RIPA divt4j_techrepublic@... | 10/02/07
DriveCrypt Plus Pack and "plausible deniability"? divt4j_techrepublic@... | 10/02/07
Law that compels the surrender of encryption keys goes into effect in t paulmah@... | 10/02/07
Surrender of Encryption key laws unneeded in U.S. TomZnaper | 10/03/07
Agreed Veazer | 11/02/07
Hope not Larry the Security Guy | 10/03/07
patriot act, ay? yellow911@... | 10/04/07

What do you think?

White Papers, Webcasts, and Downloads

Recent Entries

TR on Twitter

Archives

TechRepublic Blogs



Quick Reference: Linux Commands
Reduce stress and speed up resolutions with the easiest command references right at your fingertips. You'll receive a PDF file covering Linux, packed with the most common commands you'll need and use daily.
Buy Now
IT Help Desk Survival Guide, Third Edition
TechRepublic's IT Help Desk Survival Guide, Third Edition provides tools and recommendations to help you better manage help desk services, improve end-user support, troubleshoot frustrating hardware issues, identify quick fixes to vexing Windows problems, and help users make the most of Microsoft Office 2003.
Buy Now

SmartPlanet

Click Here