ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Compliance Toolkit

Turning the tide against RIPA

Leader ZDNet.co.uk

Published: 15 Aug 2006 17:25 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

After six years on the shelf, the controversial Part III of the Regulation of Investigatory Powers (RIP) Act is about to be activated. This would make it illegal to fail to produce encryption keys on demand: should the suspect be unable to do so, they would have to prove that this is because they could not rather than they would not.

As those concerned with human rights have pointed out, this means proof of innocence rather than proof of guilt — a fundamental change in the way the law works. To be effective, the law must have penalties stronger than those of the laws it is seeking to back up — and as those include terrorism and paedophilia, this points to prison sentences of decades. That's unconscionably strong for the facts of the offence itself.

Then there are the technicalities of what RIP seeks to do. We have previously pointed out that with modern encryption, it is possible to have multiple keys unlocking multiple levels of security. The more secure levels can be made undetectable even after others have been revealed, leaving the suspect able to apparently comply with a request while retaining secrets. Such actions would be indistinguishable from someone complying in good faith — it is hard to prove the non-existence of something that cannot be shown to exist, even using Home Office logic. That isn't forensics, it is theology.

In short: the law is flawed in concept and implementation, and will be of dubious use in execution. It won't help the police open up the 200 encrypted computers they claim to have gathering dust, nor will it help to catch the determined, informed criminals who know enough to read up on the subject. It will doubtless be useful in persuading other, more hapless targets to do deals — as the amount of encrypted data on laptops, mobile phones and other devices increases, so does the opportunity to put the frighteners on.

The Code of Practice cannot by itself fix these flaws, but it's our last chance to make our concerns felt. It is in order to ask where the penalties for misuse of the Act are defined, what framework exists to detect such misuse, and why there is no review planned of such complex and fundamentally controversial legislation after it goes into effect. Even if we can't put down this rabid dog, we can at least ask for a muzzle.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
48 out of 88 people found this useful


Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

FMD Officer (Telemetry Systems Engineer)

Qualified in a relevant discipline, you should have experience of remote data gathering techniques and methods. The RTS is used to gather ...

IT Help Desk Analyst

To co-ordinate the communication from 2nd and 3rd line support to users managing expectations for likely fix times and call status. Key ...

Service Delivery Manager - Global B2B Supplier & Service Quality Manager

Responsible for discussing and recommending penalties to apply or credits to give based on service performance. Excellent understanding of service ...

Loading Video Player ....

Featured Talkback

There will be further activation issues to watch out for as Microsoft plans to offer a similar service to independent software vendors whereby they can "control" licensing through activation and other measures similar to the Software Protection Platform.

By: DefenceIT

Read full story:
Microsoft outage down to 'human error'

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments