ENISA: Encryption Back-Doors ‘Not A Solution’

Encryption back-doors would not improve law enforcement’s ability to gain access to criminals’ communications, and might well have exactly the opposite effect, according to
ENISA, the EU’s IT security advisory agency.

A number of governments, including those in the UK and the US, have suggested forcing communications companies to provide access to encrypted transmissions on demand, but such a system would be likely to encourage criminals to move to other services or develop their own technologies, ENISA said in a new study.

‘Punishes the wrong people’

Meanwhile, such technologies would “punish” the wrong people by making the services used for legitimate communications less secure, according to ENISA.

Any back-door system put into place would be likely to be targeted by criminals and nation-states looking to spy on users’ messages.

The resulting mistrust by the public could threaten the advancement of the EU’s plans for a digital single market.

“An analysis should be carried out to analyse the benefit to law enforcement of the introduction of backdoor weakened encryption technology as against the potential damage to the take up and operation of the Digital Single Market before any legislation is introduced,” ENISA said in the study, titled Strong Encryption Safeguards Our Digital Identity.

The opinion paper made particular mention of services such as WhatsApp, which uses an end-to-end encryption technique originally developed by Open Whisper Systems for the Signal mobile messaging application.

End-to-end encryption

Such techniques, which share encryption keys between users without storing them, make tapping calls “very difficult”, ENISA said.

“There is every reason to believe that more technology advances will emerge that will continue to erode the possibility of identifying or decrypting electronic communications,” the agency wrote.

Other problems with introducing back-doors include the overhead cost for provisioning such a system and the possible weakening of other technologies, such as digital signatures, that rely on encryption.

“History has shown that technology beats legislation and criminals are best placed to capitalise on this opportunity,” the paper concluded.

The current British government recently passed controversial legislation nickamed the “Snooper’s Charter” intended to legitimise broader surveillance practices, including obliging Internet services providers to store users’ communications records and make them available to government agencies.

How much do you know about privacy? Try our quiz!

Matthew Broersma

Matt Broersma is a long standing tech freelance, who has worked for Ziff-Davis, ZDnet and other leading publications

Recent Posts

Virgin Media O2 To Invest £700m To ‘Transform’ 4G, 5G Network

Virgin Media O2 confirms it will invest £2m a day for new mobile masts, small…

12 hours ago

Tesla Cybertruck Deliveries On Hold Due To Faulty Side Trim

Deliveries of Telsa's 'bulletproof' Cybertruck are reportedly on hold, amid user complaints side trims are…

13 hours ago

Apple Plots Live Translation Option For AirPods – Report

New feature reportedly being developed by Apple for iOS 19, that will allow AirPods to…

14 hours ago

Binance Token Rises After Trump Stake Report

Binance BNB token rises after WSJ report the Trump family is in talks to secure…

1 day ago

iRobot Admits ‘Substantial Doubt’ Over Continued Operation

After failed Amazon deal, iRobot warns there is “substantial doubt about the Company's ability to…

1 day ago

Meta’s Community Notes To Use X’s Algorithm

Community Notes testing across Facebook, Instagram and Threads to begin next week in US, using…

1 day ago