India's Worrying Draft Encryption Policy 114
knwny writes: The government of India is working on a new National Encryption Policy the contents of which have raised a few alarms.Among other things, the policy states that citizens and businesses must save all encrypted messages (including personal or unofficial ones) and their plaintext copies for 90 days and make them available to law enforcement agencies as and when demanded. The policy also specifies that only the government of India shall define the algorithms and key sizes for encryption in India. The policy is posted on this website.
This should be interesting. (Score:5, Interesting)
Re: (Score:3)
If you are attacked with malware that encrypts your drive, the government questioning your encryption probably is the least of your concerns.
Uhhh. What?
Plus, you cannot be held responsible for things that you have no control over.
False. [wikipedia.org]
Re:This should be interesting. (Score:5, Interesting)
What happens if, by accident or malicious intent, the storage medium you are using is destroyed? Or ironically enough, if you are attacked with malware that encrypts your drive. How do you explain that you can't decrypt the drive to so they can decrypt your messages? Or that the cloud solution provider you were using is down for a undetermined amount of time?
It depends what you are accused of and how politically connected or rich you are. Seriously, a law like this is meant as a catch all that nobody will be able to ensure their compliance with. Basically it outlaws encryption for all practical purposes. So if you are accused of something, anything, and you happened to use encryption then at least they can jail or fine you on a technicality when they can't prove that any real crime has been committed.
Re: (Score:1)
This is like the UK's RIPA law. Say you do a SSL transaction with PFS enabled, you can be hauled into Crown Court, the judge asks for the session key (which is obviously long gone), and the dialog goes like this:
Magistrate: "What is the session key to your web browsing session at www.cowsrus.com?"
Arrestee: "No clue."
Magistrate: "That is another four years to your sentence. Now what is the session key to your web browsing session at www.cowsrus.com?"
Repeat until a life sentence is achieved. This is an
Re: (Score:1)
Governments have no rights. . They only have power and authority and chains of obedience.
Re: (Score:2)
India is a democracy, government has all the rights the people give it.
Re: (Score:1)
No. Democracies with no constitutional restrictions on government presume to possess all possible powers, limited only by The People getting outraged over something and demanding revokation.
The People haven't given them a damned thing -- those in power just took it.
A proper government is formed by granting a list of powers to it, "and none others".
Re: (Score:2)
so you are not arguing if its a democracy.. just not one you consider proper... again power is still with the people, what they choose to do with it... then again encryption is not really on the radar for most indians and much more immediate quality of life issues probably are... not much traction on those either. so ... lets just blame the culture :)
Re: (Score:2)
Re: (Score:3)
If you're interested in protecting that you would not do any buisiness with India in the first place.
Re: (Score:2)
Re: (Score:2)
And that may be the kicker. Outsourcing to India is dead if this gets to law and common practice.
Re: (Score:2)
They're authoritarian morons, like most politicians and government officials in the security theater industry. Simpering, contemptible, evil morons.
Do you have to prove they are no fake (Score:2)
... or can you simply store some arbitrary log, and tell them it's your actual communication data?
In other news... (Score:4, Insightful)
Re: (Score:3)
The scary part is that many people will...
Re: (Score:2, Offtopic)
Re: (Score:2)
Yet another failed attempt ... (Score:5, Insightful)
And here we go with yet another example of politicians and other assholes with no technical understanding deciding to legislate "solutions" for their needs without the barest understanding of reality.
Yet another country who has decided their need to spy magically changes how technology works.
And, as usual, this will never work in practice.
Re: (Score:1)
Re: (Score:2, Interesting)
You're under the mistaken impression that this legislation has anything to do with encryption, technology, or is in any way designed to solve a problem for the public.
Short, un-pc but painfully true answer: India is an apartheid state run by privileged class. (Cue shill posters in 3..2..1.. Sorry. India's been like this for 5-10x longer than most other countries have flown their flags period. Its not changing any time soon.)
They've got two goals: 1. Make sure that the lower classes stay impoverished by limi
Re: (Score:2)
What do you expect from a country run by Tata consultants?
Re: (Score:2)
Re: (Score:3)
too late for me, I already burned my rot13 card.
try getting THAT data back, suckers!
No Exceptionalism For You! (Score:2)
It's this kind of foolishness which means that countries like India and China will never advance into the first rank of nations. It is part of a pattern of meddling, obstructiveness, distrust and plain lack of freedom that causes backwardness. I chuckle whenever a pundit proclaims that India is the future.
I hasten to add that American politicians, regulators and the general public now seem intent on thrusting the US backwards, by the same means. America will never be overtaken, but it may fall by the waysid
Re: (Score:2)
You forget about the BS America has pushed in it's past? Clipper chip? PGP fight? 40-bit export encryption.
Re: (Score:2)
You did not bother to read my second paragraph??
reactions (Score:4, Insightful)
Re:reactions (Score:5, Funny)
Agent 2: Oh, look how cute this one is!
Re: (Score:3)
Agent 1: Wow, this guy sure likes sending photos of kittens. Agent 2: Oh, look how cute this one is!
Wonder why the second picture file is named operation_curry_storm.jpg?
Re: (Score:2)
LOL, however google search did not reveal anything..
Re: (Score:2)
What is the state of steganography these days?
Hiding in plain sight seems to be a pretty good technique in the physical world and in the computer world it would seem to be a terrific to combine with encryption to make the encrypted data hard to identify.
Especially in today's world where people are constantly sharing images, videos, etc.
I'm also curious about using steganography in transport protocols -- steganographic data or parameters in HTTP/S requests and responses that would otherwise decode as meaning
Re: (Score:2)
Why have [key size and algorithm limitations] When they have enforced key escrow and mandated plaintext retention of said encrypted data?
1) So they can eavesdrop without warning the target.
2) So they can (try to) crack the saved info when somebody says the dog ate his retained data.
3) So they can have evidence to bust people who don't provide "retained data" that matches what was sent.
4) The two sets of requirements are belt-and-suspenders. The retention/delivery requirements help cover for times the wiret
Doesn't make sense (Score:5, Interesting)
Re:Doesn't make sense (Score:4, Funny)
Not to mention all of your spam e-mails that you looked at via HTTPS webmail. Because if you don't keep an unencrypted copy of "herbal viagra for sale by nigerian princes whose daughters want to video chat with you" for 90 days then you're breaking the law!
Re: (Score:3)
If I'm accessing an https website in India that would mean that I would have to copy everything I typed in and save it for 90 days.
And the other end would have to save all your form data in plaintext for 90 days, too. (I presume you mean "If I'm in India, accessing a https website" and not what you actually said; if you're not in India, or an Indian citizen, you're not bound by these laws.)
Algorythms and Key Sizes but... (Score:4, Interesting)
I see nothing about the number of iterations. There are going to be an awful lot of pissed off spys when they find that decrypting a messages gives them another encrypted message
Comment removed (Score:3)
Re: (Score:2)
anyone outsourcing to india or china already has shown their hand:
1) they care nothing about quality and are there ENTIRELY because of low-cost labor
2) they care nothing about security; they never did. its only about #1
As usual (Score:2)
It will be ineffective and it will be wielded against people who haven't even abused the law.
What's interesting about this proposal is that it actually includes a proviso that makes some sense. They want you to retain the unencrypted copy so that they can sniff through it, but shockingly, they don't want you to retain it forever. That seems like an admission that there are some secrets which should be protected by cryptography.
Re: (Score:3)
The problem, though, that even the 90 day limit is too much to require. Suppose you go to check your Gmail account. You've accessed it via HTTPS which means it's encrypted which means you now need to keep unencrypted versions of all of your e-mails for 90 days. Yes, even that Nigerian prince e-mail that you immediately went to delete as spam. First, you must save it without encryption and only then can you delete it. This will either a) make using any form of encryption too much of a hassle thus leavin
These backwards countries... (Score:4, Funny)
Aka, The "China, Please Snarf My Data" Bill (Score:4, Insightful)
So, the Indian Govt thinks that intentionally weak crypto and forced plain text long term storage is a good idea? Never mind what the US might do with this. India's strategic and economic competitor is China, which will thus get so much more info product with so much less effort.
On the flip side, this may be so unacceptable to the business sector that it'll become another source of graft for officials to look the other way. Aka, The "Bureaucrat Bonus" Bill. Something for everyone.
Government to industry: Empy wallet (Score:2)
Any DRM exceptions? (Score:5, Funny)
Waitaminute. If an Indian watches a DRMed movie, he'll be required by law to have cracked it and ripped it? If I sell DRMed media to Indians, am I going to automatically be a conspirator, if my customer doesn't crack it?
There needs to be a DRM exception.
And I'd rather not discuss the consequences of such an exception. ;-)
Strange Decision (Score:2)
Tell Narenra Modi regime to fuck off (Score:1)
Tell Narenra Modi regime to fuck off https://www.change.org/p/prime... [change.org]
Re: (Score:2, Offtopic)
Steganography in cow pictures?