// COMPLETE THREAD

UK domestic crypto regulation proposal *is* Clipper

2 expanded posts ยท every known parent and child

NODE 193da57dUK domestic crypto regulation proposal *is* Clipper
I've seen several comments on cypherpunks that misconstrue the UK proposal.
E.g. Phillip Hallam-Baker said:

> First off the proposals are not intended as a Trojan horse for
> the Clipper chip "or any other colonial scheme".
> ...
> They are emphatically not trying to introduce a Clipper chip proposal.

Unfortunately, I believe he is wrong.  It's worse than Clipper, since
it outlaws the competition.

The proposed legislation would make it illegal to offer the UK public
any service related to key management, including simply signing
peoples' keys, without being licensed by the state.  This licensing
scheme includes a GAK requirement, an interoperability requirement,
and a whole pile of requirements that may need a little translation.

This means that there would only be *one* public-key infrastructure in
the UK (they claim this as a feature for end-users, since it provides
interoperability -- though they apparently haven't picked *whose* PKI
they are going to enshrine as a monopoly).  Unfortunately it would be
completely subverted by the government.  Users would have no choice
about whether to use a different infrastructure, say from another
country, or by setting it up themselves using PGP, Secure DNS, or
whatever.  The "trust" they offer is 100% sham, since you yourself
don't get to pick who you trust.  They do.

"It will be necessary to ensure that TTP security personnel are
competent, suitably qualified, trusted, & have successfully completed
a recognised security vetting procedure."  Translation: "Public key
certification authorities will need a security clearance."

"Checks will need to be undertaken to ensure that the background and
other business interests of [TTP company] directors would not
compromise the trust placed in a TTP."  And later, "Checks will be
made to ensure that those who own, or effectively control, an
organisation, are suitable candidates for ownership of a TTP."
Translation: "We will only license people who we believe will turn
over anyone's key on demand.  If they show any sign that their
customers could actually trust them to keep private keys private,
their license will not be approved."

It explicitly states:

	It will be a criminal offence for a body to offer or provide
	licensable encryption services to the UK public without a
	valid license.

This isn't a requirement on USERS, it's a requirement on OFFERERS.
However, what this means for users is that if you want to use digital
signatures, you have to use a Traitorous Third Party.  It will be
illegal for anyone else to offer you a digital signature service.
Perhaps you could use encryption without using digital signatures, but
you've just lost most of the benefits of public-key cryptography.

I believe the proposal outlaws Secure DNS services.  Merely signing
the keys of sub-domains, for free or for money, would be illegal.  You
will only be able to secure the Internet if you first subvert the
Internet by turning over the keys.

And while the government mentions in several places that it isn't
interested in access to authentication keys, the proposal still
requires that anyone providing authentication services (like signing
keys) be a licensed TTP and subject to GAK.

	John Gilmore
NODE 03de280dRe: UK domestic crypto regulation proposal *is* Clipper
> 
> I've seen several comments on cypherpunks that misconstrue the UK proposal.
> E.g. Phillip Hallam-Baker said:
> 
> > First off the proposals are not intended as a Trojan horse for
> > the Clipper chip "or any other colonial scheme".
> > ...
> > They are emphatically not trying to introduce a Clipper chip proposal.
> 
> Unfortunately, I believe he is wrong.  It's worse than Clipper, since
> it outlaws the competition.
> 
> The proposed legislation would make it illegal to offer the UK public
> any service related to key management, including simply signing
> peoples' keys, without being licensed by the state. 

After making my first posting I re-read the last half of the DTI proposal
and came to the same conclusion as Gilmore. The first half explicitly
denies that they are enforcing GAK, then the specific legislative
proposals propose GAK.

Like much of the governments activities the DTI report is transparently
deceitfull. 

Fortunately there is no need to get too worked up about it. Its a green
and these proposals will go nowhere if the Tories lose the election.
Since they are twenty points behind and curently facing fresh allegations
of bribe taking this does not seem very likely.

The current Home Secretary is a walking civil rights threat. So far he has
abolished the right to silence, to demonstrate and is haulled up in front 
of the courts for abusing his office on a practically monthly basis. GAK
would be the least of worries were they to be elected.

Unfortunately his Labour shadow appears to have been trying to out-thug
him. If Howard proposed the return of hanging Straw would demand drawing
and quartering. 

Since the Labour opposition have been the target of a considerable amount of
improper use of wire-taps and other forms of surveillance there are many 
who are likely to be very usefull allies.

The real question is whether the pro-crypto message becomes widely known 
before the civil service starts whispering in ministers ears.


	Phill