Government would be barred from mandating crypto backdoors under House bill
Full article664 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
A bipartisan group of House lawmakers wants to bar the federal government from mandating “backdoors,” or configurations that enable surveillance, in commercial software and hardware products.
A bipartisan group of House lawmakers on Thursday reintroduced legislation that would bar the government from mandating “backdoors” — configurations that enable surveillance — in commercial software and hardware products.
The move is the latest salvo in a long-running legislative fight over law enforcement access to encrypted communications, and it comes after a Senate committee recently sought input from big technology firms on regulating encryption. Law enforcement officials say encryption has hampered investigations by preventing access to suspects’ communications, while cryptographers warn that weakening encryption could greatly undercut digital security for everyday people.
“It is troubling that law enforcement agencies appear to be more interested in compelling U.S. companies to weaken their product security than using already available technological solutions to gain access to encrypted devices and services,” Rep. Zoe Lofgren, D-Calif., one of the bill’s sponsors, said in a statement. She introduced the bill in 2014 and has repeatedly sounded the alarm on backdoors since.
The Secure Data Act would prohibit agencies from mandating or requesting a “manufacturer, developer, or seller of covered products [to] design or alter the security functions in its product or service to allow” for surveillance. The bill would exempt surveillance authorized by the Communications Assistance for Law Enforcement Act.
“Backdoors in otherwise secure products make Americans’ data less safe, and they compromise the desirability of American goods overseas,” Rep. Thomas Massie, R-Ky., a co-sponsor of the bill, said in a statement.
Other sponsors of the bill include Democratic Reps. Ted Lieu of California and Jerrold Nadler of New York, and Republican Reps. Matt Gaetz of Florida and Ted Poe of Texas.
The bill’s sponsors were part of a group of lawmakers that wrote to FBI Director Christopher Wray last month slamming the FBI’s handling of the San Bernardino shooter’s locked iPhone, a landmark case in the encryption battle. The lawmakers said the bureau’s claim that it couldn’t bypass encryption on some 7,800 devices last year seemed “highly questionable.”
More than two years after the San Bernardino terrorist attack, the legislative tussle over encryption grinds onward.
On Monday, Attorney General Jeff Sessions said that Congress may need to “take action” on the obstacle he said encryption poses to law enforcement investigations. “That’s why we are working with stakeholders in the private sector, in law enforcement, and in Congress to find a solution to this problem,” Sessions told a group of state investigators, according to his prepared remarks.
CyberScoop reported last month that staffers on the Senate Judiciary Committee have been conferring with representatives of U.S. tech firms for ideas on another potential bill to regulate encryption.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/crypto-backdoor-mandate-ban-house-legislation-zoe-lofgren/