UK May Demand Encryption Keys

By Jeremy Kirk on Sun, October 01, 2006
Tweet it!
Email
Digg
Share this article
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

CIO

The U.K. government may soon activate a law that would compel a person to provide encryption keys or make scrambled data intelligible upon demand by authorities, or face jail time. The move follows British police complaints that increasingly, PCs containing encrypted data are stalling investigations in areas such as child pornography.

In 2000, Parliament passed the Regulation of Investigatory Powers Act (RIPA), updating how law enforcement should conduct covert surveillance and wiretapping in light of new communications technologies.

But the government didn’t activate a part of the law dealing with encryption—because it wasn’t widely used at the time, according to the Home Office. However, the government recently made an exception. As part of antiterrorism legislation approved in April, suspects in national security cases could face five years in prison for failing to disclose an encryption key.

Under RIPA, suspects may receive up to two years in prison for cases outside national security. But the legislation has worrisome aspects, security experts say. High-ranking military, police and customs officials could demand keys without a court warrant.

Multinational corporations may be nervous about storing encryption keys in that kind of climate, says Richard Clayton, a security expert at the University of Cambridge in Cambridge, England. "There is a case for a power to ask for decryption," he says. But "almost everybody charged with this offense is going to say "I forgot the key,’ and frankly, a jury is going to believe them," he adds.

$firstKeyword

Get up to speed on IT recruiting.

Learn More »
Loading...
Most Recent Compliance Stories
Automation makes compliance part of day-to-day operations, enabling CIOs to shift time to more important things-like a security strategy that protects the business, rather than simply pleases an auditor. Read this exclusive white paper from compliance leader Tripwire to learn how a Protect, Detect, and Correct compliance strategy can give you back your most precious resource: time.
For many companies, regulatory compliance can already be an overwhelming and confusing area to navigate, and the need to comply with the PCI DSS might feel like yet another burden...
Organizations spend more money on risk management and compliance than they should, largely due to inefficiency. In a complex and changing business environment, manually managed and fragmented risk and compliance programs can cripple organizations' agility, performance, and competitiveness. Success therefore requires that an or­ganization integrate, build, and support business process with an enterprise view of risk and compliance. Governance, risk, and compliance (GRC) software can and must deliver value towards this goal.
Enterprises today do not want to be pinned down to one type of architecture. Instead, they want to enjoy global application delivery via a blend of physical, virtual and cloud computing environments. With F5, IT can provide that flexibility without risking application performance and reliability. This white paper explains how.
A report on why market-leading companies use business analytics to their competitive advantage.
Forrester Research conducted in-depth interviews with users who moved from multiple automated point solutions to Application Performance Management.
Grappling with a sprawl of printing and imaging devices across your organization? It's not uncommon today. Many IT leaders say they lack insight into how devices are being used, which ones need updating, and how to best allocate assets across their company. This challenge is causing escalating costs and is creating inefficiencies. In this webcast, we explore managed print services: what it is, how it improves workflow and why it ultimately reduces IT costs.
Join Aternity, a Gartner Cool Vendor in IT Operations, for a live demo on how Fortune 500 companies are leveraging our award-winning platform to deliver a user-centric approach to Proactive IT Management.

When: Sept. 15th / 11 AM PT / 2 PM ET
Watch this on-demand Webinar with Elaina Stergiades, IDC senior research analyst, to discover how IT organizations can better meet the needs of their internal customers.
This webcast, featuring Jim Malone, Senior Editorial Director from IDG Solutions Group and Juan Jones, Senior Vice ...
New Age of Collaboration - Study Reveals a Balancing Act Between Culture and Technology
Strategic planning is critical for your success, yet new research shows it often falls short in even the best organ...
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Resource Center