https://www.zdnet.com/article/kazakhstan-government-is-inter...
The EU is following this govennment friendly move:
https://www.bleepingcomputer.com/news/security/experts-urge-...
It would not be difficult for India as well. I see itlikely Modi and BJP will make this move as part of some anti-terrorist legislation.
The problem is that those keys can't be used passively. Just knowing these keys achieves nothing (lay people often assume you could snoop TLS, but, that's not how it works with a CA root even in archaic SSL versions) The only useful thing you can do with those keys is make certificates (the thing the CA gets to do legitimately) but presumably you'd make bogus ones.
But in most of the world's web browsers those certificates don't work unless they come with SCTs, receipts from two or more public certificate transparency logs promising they logged these certificates.
So now as well as obtaining private keys to a trusted root CA, you need to break at least two of the CT logs.
This deliberately and unavoidably creates a paper trail showing what happened. All three entities (the root CA and two logs) have their reputations destroyed and if they're for-profits presumably go bankrupt (or the business unit fails).
And what did you get for this? A forged certificate? Maybe a few dozen if you targeted carefully. Maybe you were able to pull this off for a whole week before alarm bells got too loud to ignore ?
"Cryptographer Bruce Schneier says the attack may have been "either the work of the NSA, or exploited by the NSA."[6] However, this has been disputed, with others saying the NSA had only detected a foreign intelligence service using the fake certificates.[7]"
The chilling effect of it is. What if they demand you give them information you do not have a way of accessing. (Eg Signal). How would you comply? Do you have to pre-empt whatever requests you MIGHT get and ensure you could back-door a user if it were required. The law also seems to imply that ASIO could demand a single employee at a company backdoors something and they wouldn't be able to tell their co-workers.
That's what Technical Capability Notices are for. You don't have to implement a backdoor until they force you to. They have worded the legislation to make it sound as though this cannot be used to implement "systemic weaknesses" but this is bullshit (their definition of a "systemic weakness" would be something like getting a backdoor into OpenSSL, while a backdoor in Facebook Messenger is not a "systemic weakness" because it only affects one application).
https://www.hindustantimes.com/india-news/govt-proposes-law-...
But Telecom Authority of India rules out any immediate intervention.
https://tech.hindustantimes.com/tech/news/trai-rules-out-reg...
I couldn't quote from the article here but looks like they are going to wait till clarity emerges from International jurisdiction.
Which I think Signal would fall under at least one of those services.
you can control+f your way through to see everything related to that phrase.
It defines message as:
“message” means any sign, signal, writing, image, sound, video, data stream or intelligence or information intended for telecommunication;
And then it says that said "messages" can be "intercepted or detained or disclosed", for a really wide range of reasons, apparently without the intervention of a judge. 24.4 On the occurrence of any public emergency or in the interest of the public safety, the Central Government or a State Government or any officer specially authorized in this behalf by the Central or a State Government, may, if satisfied that it is necessary or expedient to do so, in the interest of the sovereignty, integrity or security of India, friendly relations with foreign states, public order, or preventing incitement to an offence, for reasons to be recorded in writing, by order:
(a) direct that any message or class of messages, to or from any person or class of persons, or relating to any particular subject, brought for transmission by, or transmitted or received by any telecommunication services or telecommunication network, shall not be transmitted, or shall be intercepted or detained or disclosed to the officer mentioned in such order;Service: here they are
Officer: decrypt for me
Service: Sorry, don't have the keys.
[0] https://www.outlookindia.com/business/proposal-to-curtail-tr...