NSA encryption-defeating efforts will backfire, privacy advocates say

The agency's work against encryption will lead to a loss of trust in the government and US companies, some say

The U.S. National Security Agency's efforts to defeat encryption will backfire by eroding trust in U.S.-based Internet services and in the agency's own efforts to aid U.S. companies with cybersecurity, a group of privacy advocates said Tuesday.

Many companies will see the NSA's dual roles of code breaking and helping U.S. companies with cybersecurity as clashing, following news reports of the agency's efforts to defeat online encryption, said Kevin Bankston, director of the Free Expression Project at the Center for Democracy and Technology.

The NSA has defeated encryption through a variety of means, including through reported backdoors in online services and covert compromises in encryption standards, according to news reports last month. Those reports followed revelations in June by former NSA contractor Edward Snowden about massive data-collection programs at the agency. The NSA says the data collection efforts, which include monitoring U.S. phones and overseas Internet communications, are necessary to counter the threat of terrorism.

For U.S. technology companies, it is "terribly debilitating and undermining to have the rest of world thinking there have been backdoors built into their systems to help the U.S. government," said Alan Davidson, a visiting scholar at the Massachusetts Institute of Technology and former public policy director at Google.

The NSA's encryption-defeating efforts will also hurt the agency, Davidson said at an Information Technology and Innovation Foundation discussion.

Many U.S. companies have asked the NSA for cybersecurity assistance in recent years, but "you'd be crazy to ask for that kind of help now," Davidson said. "You want to have the best mathematicians and security experts in the world to help you secure your systems. But when it's the same people who ... want to compromise the security of your system, that's probably going to dissuade you a bit."

The NSA's efforts will prompt other governments to require that their citizens' data be stored within their borders and will lead to efforts to route Internet traffic around the U.S., Bankston said. The NSA's efforts will lead to compromised intelligence-gathering capabilities in the long run as other countries seek to circumvent U.S. services and networks, he said.

"They could very easy kill the goose that laid the golden egg here," he said. "[The NSA has] been placed in a privileged position here because so much data is stored in the U.S., so much data transits the U.S. However, to the extent that it is not clear that we have strong legal standards governing the access to data ... we're going to see that data go away."

The NSA's encryption-defeating efforts will also lower trust in security standards developed through the U.S. National Institute of Standards and Technology (NIST) because of the reports that the NIST helped the NSA tamper with encryption standards, panelists at the encryption forum said.

A NIST spokesman wasn't available for comment Tuesday because of a partial government shutdown, but the agency has denied that it helped build backdoors into encryption standards.

Covertly weakening encryption standards would be "cheating in the worst way," Bankston said.

An NSA spokeswoman defended the agency's work on security standards.

"NSA is responsible for setting the security standards for systems carrying the nation's most sensitive and classified information," she said in an email. "We use the cryptography and standards that we recommend, and we recommend the cryptography and standards that we use. We do not make recommendations that we cannot stand behind for protecting national security systems and data. The activity of NSA in setting standards has made the Internet a safer place to communicate and do business."

The 2002 Federal Information Security Management Act (FISMA) requires the NIST to work with the NSA on cybersecurity standards, but little is known about how the two agencies have cooperated, said Amie Stepanovich, director of the Domestic Surveillance Project at the Electronic Privacy Information Center (EPIC). Stepanovich called on lawmakers to require more transparency in the relationship between the two agencies.

Grant Gross covers technology and telecom policy in the U.S. government for The IDG News Service. Follow Grant on Twitter at GrantGross. Grant's email address is grant_gross@idg.com.

Join the PC World newsletter!

Error: Please check your email address.

Tags Alan DavidsonInformation Technology and Innovation FoundationtelecommunicationKevin BankstonU.S. National Security AgencyElectronic Privacy Information CenterinternetprivacyGooglesecurityAmie StepanovichMassachusetts Institute of TechnologyCenter for Democracy and TechnologyU.S. National Institute of Standards and Technologygovernment

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Grant Gross

IDG News Service
Show Comments

Essentials

Lexar® JumpDrive® S57 USB 3.0 flash drive

Learn more >

Microsoft L5V-00027 Sculpt Ergonomic Keyboard Desktop

Learn more >

Mobile

Lexar® JumpDrive® S45 USB 3.0 flash drive 

Learn more >

Exec

HD Pan/Tilt Wi-Fi Camera with Night Vision NC450

Learn more >

Lexar® Professional 1800x microSDHC™/microSDXC™ UHS-II cards 

Learn more >

Audio-Technica ATH-ANC70 Noise Cancelling Headphones

Learn more >

Lexar® JumpDrive® C20c USB Type-C flash drive 

Learn more >

Budget

Back To Business Guide

Click for more ›

Most Popular Reviews

Latest News Articles

Resources

GGG Evaluation Team

Michael Hargreaves

Windows 10 for Business / Dell XPS

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Kathy Cassidy

STYLISTIC Q702

First impression on unpacking the Q702 test unit was the solid feel and clean, minimalist styling.

Anthony Grifoni

STYLISTIC Q572

For work use, Microsoft Word and Excel programs pre-installed on the device are adequate for preparing short documents.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?