FBI, NSA Want Master Encryption Keys from Internet Companies
July 25, 2013 7:06 PM
comment(s) - last by
The question of whether it's legal for them to ask for these SSL keys or not is unclear
The feds are trying to creep further into the personal lives of Web users by requesting master encryption keys from Internet companies.
According to a new report from
, the Federal Bureau of Investigation (FBI) and the National Security Agency (NSA) have both tried to obtain master encryption keys as part of their
digital surveillance efforts
, but there's a huge question as to whether they have the legal authority to do so.
Master encryption keys are crucial to Web encryption. They put contents of Web communications into code that is tough to crack using Secure Sockets Layer (SSL). If government agencies were to get their hands on these SSL keys, they could decode the content and peek into the lives of Internet users.
The NSA is also looking to get these SSL keys because it would allow for surveillance through its fiber taps, which are now heavily guarded by SSL.
SSL was originally put in place because of insecure and open Wi-Fi networks. Google adopted HTTPS (which appears in the browser to show that SSL is enabled -- back in 2010 for Gmail, and Microsoft did the same for Hotmail. Later in 2012, Facebook followed suit for its popular social network.
Now, these large Internet companies face the fear of government agencies trying to obtain the SSL keys and expose information on their users. Microsoft, Google and Facebook all said that they haven't given any SSL keys to the government, and agreed that they would fight against doing so.
Other larger companies like Apple, Verizon, AT&T, Yahoo, Comcast and AOL haven't said if they've been asked for or have given SSL keys to the feds.
But the larger companies fear that smaller Web establishments without deep pockets or a hefty legal department will give in to the government's requests for keys.
SSL has certainly hindered the government's spying abilities, which is why they're coming directly to the source for the keys. But if all else fails, the feds have other avenues of
getting what they need
. For instance, companies like Packet Forensics help government agencies import "legitimate" copies of SSL keys -- which could possibly be obtained through a court order -- for spying on users.
Speaking of a court order, it's not clear whether federal surveillance laws allow the government to ask for SSL keys -- even with subpoenas. Subpoenas call for gathering evidence related to an investigation, where SSL keys would seem to open up a treasure trove of data that may contain pieces of information relevant to an investigation, but likely most that are not.
This article is over a month old, voting and posting comments is disabled
7/25/2013 10:56:23 PM
"Congress shall make no law abridging the right of the people to engage in communication, via any communication methods presently known or currently unknown, that is subject to surreptitious monitoring without a publicly-accessible court warrant authorizing said monitoring."
Pretty please? I think it's time to just quit being disgusted with my government and ranting and raving about it in online echo chambers with like-minded individuals and actually... write my House rep and Senator. I suggest all Americans take the time to do the same. It's better than doing nothing at all.
"A lot of people pay zero for the cellphone ... That's what it's worth." -- Apple Chief Operating Officer Timothy Cook
NSA Spying Fallout Hits Defcon, Hackers Tell Feds to Stay Away
July 12, 2013, 9:00 AM
Source: Don't Worry, NSA Spies on "99 Percent" of Americans' Locations, Call Records
June 14, 2013, 3:57 PM
Vine Users No Longer Allowed to Post Pornographic Videos
March 7, 2014, 1:47 PM
Facebook Launches Slightly Tweaked News Feed
March 7, 2014, 9:03 AM
Target Chief Information Officer Resigns in Wake of Holiday Data Breach
March 6, 2014, 2:01 PM
Quick Note: Yahoo to Require Users of its Services to Have Yahoo IDs
March 5, 2014, 4:55 PM
Ellen DeGeneres' Star-studded "Selfie" Briefly Crashes Twitter During Oscar Broadcast
March 3, 2014, 8:27 AM
Comcast Deal May See Netflix Start Paying Verizon, AT&T
February 25, 2014, 9:29 AM
Most Popular Articles
Facebook Kills Popular Messenger App for PCs
March 1, 2014, 4:01 PM
Mt. Gox Bitcoin CEO Can't Stifle Grin as he Bows in Apology for Bankruptcy
February 28, 2014, 5:00 PM
Bitcoin King: Mt. Gox CEO Mark Karpelès' History of Arrests, Firings
March 5, 2014, 9:05 AM
Two More Microsoft Executives Leaving the Company
March 3, 2014, 4:38 PM
USAF Moves Forward With Long Range Bomber Program Despite Budget Crunch
March 4, 2014, 9:44 AM
Latest Blog Posts
Tesla vs. BMW: Who Has the Safer EV?
Feb 1, 2014, 2:56 PM
Justice Leaks Details of Next HTC One Two Flagship Phone
Dec 5, 2013, 4:04 PM
Global Cyber Espionage Concerns Reveal Growing Cyber Armies
Nov 29, 2013, 11:04 AM
Is The Period Becoming an Expression of Anger?
Nov 26, 2013, 2:02 PM
NSA and Congress -- You Will Never Kill the Constitution, It's an Idea
Nov 10, 2013, 2:00 PM
More Blog Posts
Copyright 2014 DailyTech LLC. -
Terms, Conditions & Privacy Information