{"id":19043,"date":"2022-05-14T10:45:04","date_gmt":"2022-05-14T18:45:04","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2022\/05\/14\/news-12776\/"},"modified":"2022-05-14T10:45:04","modified_gmt":"2022-05-14T18:45:04","slug":"news-12776","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2022\/05\/14\/news-12776\/","title":{"rendered":"The NSA Swears It Has \u2018No Backdoors\u2019 in Next-Gen Encryption"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/627ec46d5da93400b154bb93\/master\/pass\/NSA-Backdoor-Encryption-GettyImages-1335176913.jpg\"\/><\/p>\n<p><strong>Credit to Author: Lily Hay Newman| Date: Sat, 14 May 2022 13:00:00 +0000<\/strong><\/p>\n<p class=\"BylineWrapper-iiTsTb hAGfXd byline bylines__byline\" data-testid=\"BylineWrapper\" itemprop=\"author\" itemtype=\"http:\/\/schema.org\/Person\"><span itemprop=\"name\" class=\"BylineNamesWrapper-dbkCxf erRIa-D\"><span data-testid=\"BylineName\" class=\"BylineName-cKXFOb UCAzg byline__name\"><a class=\"BaseWrap-sc-TURhJ BaseText-fFzBQt BaseLink-gZQqBA BylineLink-eZnyPI eTiIvU mEZDb fNdcwQ bKZMMS byline__name-link button\" href=\"\/author\/lily-hay-newman\">Lily Hay Newman<\/a><\/span><\/span><\/p>\n<p>To revist this article, visit My Profile, then <a href=\"\/account\/saved\">View saved stories<\/a>.<\/p>\n<p>To revist this article, visit My Profile, then <a href=\"\/account\/saved\">View saved stories<\/a>.<\/p>\n<p><span class=\"lead-in-text-callout\">A group of<\/span> human rights lawyers and investigators called on the Hague this week to bring what would be <a href=\"https:\/\/www.wired.com\/story\/cyber-war-crimes-sandworm-russia-ukraine\/\">the first ever \u201ccyber war crimes\u201d charges<\/a>. The group is urging the International Criminal Court to bring charges against the dangerous and destructive Russian hacking group known as Sandworm, which is run by Russia\u2019s military intelligence agency GRU. Meanwhile, activists are working to <a href=\"https:\/\/www.wired.com\/category\/security\/\">block Russia from using satellites<\/a> controlled by the French company Eutelsat to broadcast its state-run propaganda programming.<\/p>\n<p class=\"paywall\">Researchers released findings this week that <a href=\"https:\/\/www.wired.com\/story\/leaky-forms-keyloggers-meta-tiktok-pixel-study\/\">thousands of popular websites record data that users type into forms<\/a> on the site before they hit the Submit button\u2014even if the user closes the page without submitting anything. Google released a report on an <a href=\"https:\/\/www.wired.com\/story\/google-cloud-amd-confidential-computing-security-audit\/\">in-depth security analysis it conducted with the chipmaker AMD<\/a> to catch and fix flaws in specialty security processors used in Google Cloud infrastructure. The company also announced a slew of privacy and security features for its new Android 13 mobile operating system along with a <a href=\"https:\/\/www.wired.com\/story\/android-13-privacy-security-update\/\">vision for making them easier for people to understand and use<\/a>.<\/p>\n<p class=\"paywall\">The European Union is considering child protective legislation that would <a href=\"https:\/\/www.wired.com\/story\/europe-csam-scanning-law-chat-encryption\/\">require scanning private chats<\/a>, potentially undermining end-to-end encryption at a massive scale. Plus, defenders from the cybersecurity nonprofit BIO-ISAC are <a href=\"https:\/\/www.wired.com\/story\/biotech-security-threats\/\">racing to protect the bioeconomy from digital threats<\/a>, announcing a partnership this week with Johns Hopkins University Applied Physics Lab that will help fund pay-what-you-can incident response resources.<\/p>\n<p class=\"paywall\">But wait, there\u2019s more. Each week we round up the news that we didn\u2019t break or cover in-depth. Click on the headlines to read the full stories. And stay safe out there.<\/p>\n<p class=\"paywall\">The United States is completing development of a new generation of high-security encryption standards that will be robust in the current technical climate and are designed to be resistant to circumvention in the age of quantum computing. And while the National Security Agency contributed to the new standards&#x27; creation, the agency says it has no special means of undermining the protections. Rob Joyce, the NSA\u2019s director of cybersecurity, told Bloomberg this week, \u201cThere are no backdoors.&quot; The NSA has been implicated in schemes to backdoor encryption before, including in <a href=\"https:\/\/www.wired.com\/2013\/09\/nsa-backdoor\/\">a situation in the early 2010s<\/a> in which the US removed an NSA-developed algorithm as a federal standard over backdoor concerns.<\/p>\n<p class=\"paywall\">An extensive investigation by Georgetown Law\u2019s Center on Privacy &amp; Technology reveals a more detailed picture than ever of US Immigration and Customs Enforcement agency surveillance capabilities and practices. According to the report, published this week, ICE began developing its surveillance infrastructure at the end of the George W. Bush administration, years before it was previously thought to have begun these efforts. And researchers found that ICE spent $2.8 billion on surveillance technology, including face recognition, between 2008 and 2021. ICE was already known for its aggressive and invasive surveillance tactics during the Donald Trump administration\u2019s anti-immigration crackdowns, but the report also argues that ICE has \u201cplayed a key role in the federal government\u2019s larger push to amass as much information as possible\u201d about people in the United States.<\/p>\n<p class=\"paywall\">\u201cOur two-year investigation, including hundreds of Freedom of Information Act requests and a comprehensive review of ICE\u2019s contracting and procurement records, reveals that ICE now operates as a domestic surveillance agency,\u201d the report says. \u201cBy reaching into the digital records of state and local governments and buying databases with billions of data points from private companies, ICE has created a surveillance infrastructure that enables it to pull detailed dossiers on nearly anyone, seemingly at any time.\u201d<\/p>\n<p class=\"paywall\">In a legal settlement this week, the face recognition and surveillance startup Clearview AI agreed to a set of restrictions on its business in the US, including that it won\u2019t sell its faceprint database to businesses or individuals in the country. The company says it has more than 10 billion faceprints in its arsenal belonging to people around the world and collected through photos found online. The settlement comes after the American Civil Liberties Union accused Clearview of violating the Illinois Biometric Information Privacy Act. The agreement also stipulates that the company won\u2019t be allowed to sell access to its database in Illinois for five years. \u201cThis settlement demonstrates that strong privacy laws can provide real protections against abuse,\u201d Nathan Freed Wessler, a deputy director of the ACLU Speech, Privacy, and Technology Project said in a <a data-offer-url=\"https:\/\/www.aclu.org\/press-releases\/big-win-settlement-ensures-clearview-ai-complies-with-groundbreaking-illinois\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.aclu.org\/press-releases\/big-win-settlement-ensures-clearview-ai-complies-with-groundbreaking-illinois&quot;}\" href=\"https:\/\/www.aclu.org\/press-releases\/big-win-settlement-ensures-clearview-ai-complies-with-groundbreaking-illinois\" rel=\"nofollow noopener\" target=\"_blank\">statement<\/a>. Despite the privacy win, Clearview may continue to sell its services to federal law enforcement, including ICE, and police departments outside of Illinois.<\/p>\n<p class=\"paywall\">Costa Rican president Rodrigo Chaves\u00a0said on Sunday that the country was declaring a national emergency after the notorious Conti ransomware gang infected multiple government agencies with malware last week. Sunday was the first day of Chaves&#x27; presidency. Conti leaked some of a 672 GB trove of stolen data from multiple Costa Rican agencies. In April, the Costa Rican social security administration had announced that it was the victim of a Conti attack. \u201cAt this time, a perimeter security review is being carried out on the Conti Ransomware, to verify and prevent possible attacks,&quot; the agency <a data-offer-url=\"https:\/\/twitter.com\/CCSSdeCostaRica\/status\/1516465311872172032\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/twitter.com\/CCSSdeCostaRica\/status\/1516465311872172032&quot;}\" href=\"https:\/\/twitter.com\/CCSSdeCostaRica\/status\/1516465311872172032\" rel=\"nofollow noopener\" target=\"_blank\">tweeted<\/a> at the time.<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/nsa-backdoor-encryption-security-roundup\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/627ec46d5da93400b154bb93\/master\/pass\/NSA-Backdoor-Encryption-GettyImages-1335176913.jpg\"\/><\/p>\n<p><strong>Credit to Author: Lily Hay Newman| Date: Sat, 14 May 2022 13:00:00 +0000<\/strong><\/p>\n<p>Plus: New details of ICE\u2019s dragnet surveillance in the US, Clearview AI agrees to limit sales of its faceprint database, and more.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[714,21357],"class_list":["post-19043","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-security","tag-security-security-news"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19043","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=19043"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19043\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=19043"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=19043"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=19043"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}