funsec mailing list archives

Re: British Legislation to Compel Encryption Key Disclosure


From: "Thomas C. Greene" <thomas.greene () theregister co uk>
Date: Thu, 18 May 2006 22:29:11 -0400

On Thursday 18 May 2006 8:46 pm, Jim Murray wrote:
There is also the small point that in many cases the penalty for
refusing to provide a key or decrypt a document is probably less than
that for the offense the document relates to....

It's two years for refusing to give up the key, and five years for telling 
anyone that your key has been demanded.  Embarrassing an authoritarian regime 
is always a worse crime than quietly defying it.

But the law only demands the decryption key, not the passphrase.  If you're 
using a properly-formatted 25+ character pass, then who cares if they get 
your key?  It's a problem only if there's a secret back door in the crypto 
app.  

chrz,
t.

_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: