Streaming issues? Report here
Clement Manyathela 1500 x 1500 2020 Clement Manyathela 1500 x 1500 2020
The Clement Manyathela Show
09:00 - 12:00
volume_up
volume_mute

Up Next: The Midday Report with Mandy Wiener
See full line-up
The Clement Manyathela Show
09:00 - 12:00
Home
arrow_forward

Who should be allowed access to your encrypted data?

29 March 2017 7:15 PM
Tags:
BusinessUnusual

There are growing calls for governments to be given access to people’s data. Is that fair?

Following the deaths on Westminster Bridge in London on 22 March and the news that the attacker had used WhatsApp minutes before the attack began saw the UK Home Secretary call for access to encrypted messages to be made available to authorities for occasions that justify it. It is not a new call and many other agencies around the world have suggested the same.

It seems reasonable, but misses the basis of how and what encryption seeks to do. No encryption is totally secure (quantum options come the closest though). However, creating a backdoor, in effect, renders the entire system insecure.

Confused? Here is how it works...

Our privacy is safeguarded with security measures. These include physical security like a fingerprint scanner or with access control like a password. Then there is data stored on a device or the contents of a message that is transmitted. This is where encryption comes in.

You could encode your message using a cipher to change the contents in a specific way.

Consider “Safe” is our message and our cipher was to replace each letter with the next in the alphabet which makes it “Tbgf” - it is meaningless unless you know how to use the cipher to decode it.

Using a code as we did here is also not very safe. Should it be intercepted someone could try many codes until it made sense. Computers are capable of testing many types of codes very quickly to, in effect, crack it.

Encryption limits access to the contents of a message using a formula for an equation.

There are two parts: the “public key” which is the means to create the equation and the “private key” which is the only one that can solve it.

The means to create the equation is shared with anyone, which allows a message to be encrypted, but only the person that created the key pair will be able to decode it.

Encryption as is used by services like WhatsApp uses the two keys, a public and a private key, the two parts of the equation.

When you wish to send someone a message, WhatsApp encrypts it on your phone using the public key for that message. It can’t be directly unencrypted because it is a number equation that is practically impossible to solve by testing possible options.

A very simple version would be to consider the number “15” as your public key and the equation “3x5” as your private key (they are typically prime numbers), it is easy to see that 15 is equal to 3x5 which unlocks the file.

The actual numbers are much bigger, hundreds of digits long, proving them is easy, solving them is very hard (if you are a regular of Business Unusual, you will recall how the blockchain uses a similar technique).

So how would a backdoor work?

Strictly speaking if a backdoor can be created, you enable another way for anyone to workout how to decrypt that file.

Authorities would like to think they could keep that method safe, but given how many people would need to get access to it, and that it existed would be public knowledge, the system could be compromised and rather than increasing security, you effectively remove it.

The error occurs with our understanding of how locks and keys work in the real world. A lock can have more than one key, but that key can still only open that one lock.

If someone were to make a master key, you would need to make all locks the same way and that one key would open everything.

There is very little security in a system that allows for a master key, so authorities requesting a master key are not only not likely to make their citizens more safe, they are likely to make them more vulnerable.

There is a reason we should be calling for even more security because most users are unable to keep up with the functionality of their devices and this ignorance makes them more likely to be compromised by suspect apps, or people physically gaining access to their phone.

This is a basic summary of the issue and it does not address what could or should be done to limit the use of services like this by those that will break the law or cause harm.

There are no arguments to say people should not get access to cars because they could run people over because we understand the relative threat versus benefits cars provide. However, because most of us have a limited understanding of digital security it seems justified to believe the current solutions are practical ones.

So the best answer to the question posed at the beginning (who should be allowed access to your encrypted data?) remains, for now, no-one without your express permission.


29 March 2017 7:15 PM
Tags:
BusinessUnusual

More from Business Unusual

Maize field mealie farm farmer agriculture 123rf 123rfbusiness 123rflifestyle

Regenerative agriculture - an idea 12 000 years in the making

21 October 2020 7:15 PM

The future of agriculture may draw more from its past than the present

Share this:
Read More arrow_forward

battery-charging-aa

South Africa needs batteries, here are some we might use

14 October 2020 7:15 PM

Over 1000 MW of renewable energy will be added to the grid in the next year, we need a way to store it.

Share this:
Read More arrow_forward

Stock indicator candlesticks 123rf business

A business bedtime story about Robinhood

7 October 2020 7:15 PM

New investment platforms are making it easy and cheap to invest, what could go wrong?

Share this:
Read More arrow_forward

Recycling logo

An inconvenient truth - plastic recycling does not actually work

30 September 2020 7:29 PM

Most plastic was never intended to be recycled, but we have believed the story for decades

Share this:
Read More arrow_forward

123rf smart home automation

Are you ready to make your home smarter?

9 September 2020 7:30 PM

The cost and benefits are making home automation easy and affordable

Share this:
Read More arrow_forward

stock price line chart candlestick

How the Dow Jones Industrial Index tracks the state of the US stock market

2 September 2020 7:47 PM

Almost a century after it began the last original stock is removed from the index

Share this:
Read More arrow_forward

invitation to fight emoji 123rf

Epic, Apple and Google, who is the bad guy?

19 August 2020 7:15 PM

You be the judge and consider the potential arguments and outcomes

Share this:
Read More arrow_forward

Dandelion flower

It has not been a good year for rubber

12 August 2020 7:15 PM

The wheels may be coming off for the substance gets us around the world

Share this:
Read More arrow_forward

Crisis just ahead dark clouds thunderstorm 123rf 123rfbusiness

A warning for the future, we do not think enough about our actions

5 August 2020 7:15 PM

Despite being one of the few animals that think about the future, we don’t think far enough

Share this:
Read More arrow_forward

Dumpster Fire Bill Ward Flickr

How social media became a dumpster fire and what to do about it

29 July 2020 7:15 PM

While it may feel things are getting worse they are starting to get better

Share this:
Read More arrow_forward