Russia says it can collect encryption keys to decode information from WhatsApp
ibtimes.co.uk
ibtimes.co.uk
> After signing controversial anti-terrorist legislation earlier today, President Putin ordered the Federal Security Service (the FSB, the post-Soviet successor to the KGB) to produce encryption keys to decrypt all data on the Internet. According to the executive order, the FSB has two weeks to do it. Responsibility for carrying out Putin's instructions falls on Alexander Bortnikov, the head of the FSB.
https://meduza.io/en/news/2016/07/07/putin-gives-federal-sec...
> Russian President Vladimir Putin said Thursday at a media forum in St. Petersburg that the Internet is a “CIA project” that is “still developing as such,” the Associated Press reports.
Maybe they'll offer $1K for someone who comes up with the solution. Saves the FSB having to put a staffer on it.
http://news.softpedia.com/news/russia-finalizes-procedures-f...
Snowden revelations showed up that internet have been used as a tool to collect intelligence about foreign and domestic citizen by USA agencies. You can refresh your memory here [1]. Also, meduza.io is not a credible source as i have noted few times in my comments.
[1] https://en.wikipedia.org/wiki/Edward_Snowden#Revelations
It's trivial for a messenger app to include code that sends a copy of your private key to the messenger app's company's HQ, if served with a warrant or if obliged by law (and that seems to be precisely what's happening here).
If the messenger app is open-source (like Telegram or Signal), you can satisfy yourself that the messenger app isn't sending your private key behind your back.
But it's a different story if the app is closed-source and its parent company was involved in PRISM (like Whatsapp).
But only if you are building and installing the app from source, and have audited each release. OS apps installed through app stores suffer the same lack of visibility as a CS app.
It only says that the method with which the companies will be able to give them the encryption keys is approved.
Still, my russian may be rusty, but it seems to me, the FSB just documented a procedure which the companies will need to follow to provide the FSB with the keys.
That. No details are available. People say they have no idea how to accomplish this.
This law is just reason to ban every messenger who will not send traffic to FSB.
Of course there's also the theory, that even governments are sometimes just stupid.
Is it possible to correct the title? It's actively misleading now.
On the other hand there were rumours that Russia can and does manipulate SS7 e.g. to get 2FA tokens via SMS, they also have likely control over the GSM and 3G/4G stations. As this is a black box it's probably not impossible that a network operator could access the keys via the baseband if there is a hole a "feature" e.g. for DMA access from the baseband to the phone, however this is pure speculation from my part.
The companies themselves do not have keys to provide to anyone.
A few years ago I'd never have proposed this.. but the willingness of second and third world governments to abuse the internet for their obviously crooked purposes has reached a fever pitch in recent months.
slightly unrelated, but interesting, those same countries produce most of the world's spam and viruses.
edit: I wonder if it'd be feasible to ban corrupt governments from the internet while allowing citizens access.
And it's been undermined by Americans, and been corrupted into a platform for American surveillance and cultural propaganda, thanks to the NSA and CIA.
The thing is, Putin sounds like a raving loon for saying things like "the internet is a CIA project," but he's not entirely wrong. The US created one of the greatest tools for freedom, communication and expression the world has ever known... and it's been been trying ever since to burn it down and plant the Stars and Stripes in the ashes.
That would certainly be challenging to do, but I believe it would be possible.