Advertisement
Promo

Security management Toolkit

RIP Act gives police power to decrypt data

Tom Espiner ZDNet.co.uk

Published: 03 Oct 2007 16:14 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The police have been given powers to demand that businesses' data is decrypted.

On Monday, Part III of the Regulation of Investigatory Powers Act 2000 (RIPA) came into effect. Under Section 49 of RIPA Part III, police can serve a notice that requires encrypted data to be "put into an intelligible form" or, in other words, decrypted.

Failure to comply with a Section 49 notice can result in a two-year jail sentence, and failure to hand over an encryption key to the police can result in a five-year sentence.

The law is intended to make it more difficult for criminals and terrorists to use encryption to hide data.

However, a security researcher from the University of Cambridge's Computer Laboratory, Richard Clayton, warned that the law could have unintended consequences for businesses. "Once you hand over the key, it's risky because confidential documents could be exposed. Those documents may not contain evidence of wrongdoing, but the police may find more than they're entitled to," said Clayton, who is also an adviser to the House of Lords Science and Technology Committee.

Given the choice, security professionals will not keep their encryption keys in the UK, argued Clayton. He added that those companies using SSL encryption keys that only have premises in the UK may have no choice but to comply with a Section 49 notice.

"The security profession is all about reducing risks. International companies [such as banks] will keep it in Zurich," he said.

Sentry Posts Blog

Sentry Posts Blog
Guarding the network

What you need to know — and what you and your peers have to tell us — about security management in our new community group blog

Read more +

According to Clayton's blog, there are some defences in the statute to failing to comply with a notice — one of which is that you can claim to have forgotten the passphrase for the decryption key.

"It's a perfectly sane argument," said Clayton. "It's certainly true that a lot of people forget a lot of keys. Whether you are being truthful is a matter for a jury to decide in the end."

In some scenarios it would be obvious if a defendant were lying about having forgotten a key, said the expert. "Try asking a bank if they've forgotten their master key." But Clayton warned: "This will not be a widely used law, or be very effective when it is used. It's just going to make everyone a bit twitchy."

The Home Office said that encryption keys would be demanded only if a business wasn't able to provide the corresponding data. "The police can't just ask for a password — they do have to take into account the needs of the business and their security processes," said a spokesman.

The spokesman argued that the process was adequate because it will be overseen by the National Technical Assistance Centre (NTAC), a decryption agency.

But civil liberties campaigners have previously criticised NTAC, branding it unaccountable.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
17 out of 19 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments

Featured Talkback

In association with Network Liberation Movement
It seems to me this is a burden being placed on the wrong shoulders. There is not an It system in the world that can stop an individual taking information in their heads and spewing out at the nearest undesirable third party.

By: RonaldWilkins

Read full story:
Deloitte: People are still weakest security link


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters