Advertisement
Promo

Security threats Toolkit

BSI security code prompts criticism about key escrow

Will Knight ZDNet.co.uk

Published: 21 Jul 1999 14:39 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The BSI's Information Security Management (BS 7799), launched yesterday, is the fruit of labours started by the DTI and a group of blue-chip British companies in 1995. It contains guidelines for the whole remit of computer-related business practices, including the problematic business of encryption.

A BSI representative says: "Security has become an issue in the news over the last few months with people having their computers compromised. But this is more about promoting e-commerce and attracting clients than scare-mongering."

Companies can gain accreditation under the new code after applying to the DTI. A number of companies including Link, which manages 90% of the UK's ATM cash machines, have already been accredited.

The new code's guidelines on encryption, in section 10.3, explain the importance of adhering to both national and international law when using this technology. This will no doubt reassure companies concerned about the legal implications of encryption, but civil liberty campaigners remain unimpressed.

Stefan Magdalinski, of Stand.org, said: "The imposition of Public Key Escrow schemes is both damaging to civil liberties, and places severe burdens (financial, and technical) on the implementation of viable e-commerce sites. Furthermore, it does not significantly help law enforcement, but fundamentally weakens the security of the encryption itself, by introducing a single point of weakness."

This news comes as American scientists announce a breakthrough in encryption technology. Researchers at the US Department of Energy's Sandia National Labs yesterday revealed their Encryptor chip, capable of encrypting data at 6.7bn bits per second. This is sufficient to be used for the first time on the 2.5 Gbs and 10 Gbs channels used to carry a large volume of Internet traffic. It is also 10 times faster than any existing cryptography device, making in easier to send large amounts of encrypted data.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
43 out of 78 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Video icon

Video

Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters