Tech giants silent on new Russian surveillance law
Full article740 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
U.S.-based tech giants appear set to silently ignore new Russian laws requiring them to hand over encryption keys to internet communications to state security agencies, those tracking the issue tell FedScoop
U.S.-based tech giants appear set to silently ignore new Russian laws requiring them to hand over encryption keys for internet communications to state security agencies, those tracking the issue tell Cyberscoop.
Only two encryption providers appear to have publicly responded to the new legislation, known as ‘Yarovaya law,’ after the hardline lawmaker responsible for drafting it. One virtual private network provider, Private Internet Access, announced they were leaving Russia, while another, NordVPN, doubled down on their presence there, according to interviews and public statements.
But according to Eva Galperin, a global policy analyst for the Electronic Frontier Foundation, ‘the tech giants show no signs of complying — not Google, not Facebook, not Twitter.’
Galperin expects these large U.S.-based companies to treat the new law’s mandates as they did the data localization requirements Russia passed into law last year — which companies have basically ignored.
‘[Companies] are staying publicly silent and not complying with the data localization mandate,’ she told FedScoop. ‘None of those companies keep their Russian user data in Russia’ as the law supposedly requires, she added.
‘There’s no evidence they’ll do anything different’ with the new law — although the agency charged with enforcing the encryption mandate is the feared KGB successor, the FSB, rather than the Russian telecom regulator, which has enforcement authority under the data localization law.
She said that many providers — like messaging giant WhatsApp — used forms of encryption which made it ‘literally impossible’ for them to comply.
‘But that’s the point,’ she said. ‘There is no expectation on the part of the authorities that it is possible to comply. They know this … But it makes all the companies lawbreakers.’
The fact that pretty much any company providing state-of-the-art encrypted messaging will be in violation of the law is a ‘feature not a bug’ of the new law said Galpin. ‘It gives [the government] leverage.’
‘The companies for whom this is a real problem are the Russian telecom providers,’ she added, who face huge data retention mandates quite separate from the encryption requirements. ‘They have said [the law] will cost them trillions of roubles.’
One foreign company, Panama-based NordVPN, is ‘doubling down’ on it’s commitment to privacy and anonymity in Russia, according to Jodi Myers, the company’s head of public relations and marketing.
‘Our aim is to make this simple, for the less technical user,’ she said. But she added the firm was taking steps to ‘double encrypt’ traffic from its Russian users. ‘We do not have the key [to unlock their users’ encrypted internet traffic] and we do not store any customer data on our servers — not in Russia, not anywhere.’
So even if NordVPN’s servers in Russia were seized, the authorities would not be able to learn anything about their customers web-browsing habits from it, she said.
This didn’t stop authorities from seizing the servers of another ‘zero-log’ or no-data VPN provider Private Internet Access. The company said it was pulling out of the country after its servers were seized.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/tech-giants-silent-on-new-russian-surveillance-law/