ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Is It Really Encrypted When the Key Is Public and Automatic?

    IT Discussion
    encryption software legal
    9
    59
    4.1k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • scottalanmillerS
      scottalanmiller @Kelly
      last edited by

      @Kelly said in Is It Really Encrypted When the Key Is Public and Automatic?:

      In the state of Colorado the law is written such that if an encryption key is obtained the data is considered compromised.

      That's the case in most places, I think, but good to know as we have loads of people in CO with this.

      1 Reply Last reply Reply Quote 0
      • KellyK
        Kelly @DustinB3403
        last edited by

        @DustinB3403 said in Is It Really Encrypted When the Key Is Public and Automatic?:

        @Kelly said in Is It Really Encrypted When the Key Is Public and Automatic?:

        In the state of Colorado the law is written such that if an encryption key is obtained the data is considered compromised.

        Obtained by whom? The customers, the vendors, someone else?

        Does that mean if the rightful customer has the key, that they must consider their system compromised even though they should have the key?

        It is a privacy law. If someone who is not authorized has both the data and the key the data is considered to have been exposed and the company is liable under HB11-1828. If the key is public then any access to the data would be considered a breach and exposure.

        DustinB3403D scottalanmillerS 2 Replies Last reply Reply Quote 0
        • DustinB3403D
          DustinB3403 @Kelly
          last edited by

          @Kelly said in Is It Really Encrypted When the Key Is Public and Automatic?:

          not authorized

          Gotcha, so it's not a poorly written law but only applies in the case of not authorized cases.

          KellyK 1 Reply Last reply Reply Quote 0
          • KellyK
            Kelly @DustinB3403
            last edited by

            @DustinB3403 said in Is It Really Encrypted When the Key Is Public and Automatic?:

            @Kelly said in Is It Really Encrypted When the Key Is Public and Automatic?:

            not authorized

            Gotcha, so it's not a poorly written law but only applies in the case of not authorized cases.

            Well, it will need to fleshed out via case law to determine what unauthorized really means and how you can verify the access or prove non access. The control is ahead of technology implementation in most organizations. We will see how it plays out. It is written in sufficiently broad terms that the access could be from an external access or an internal one.

            1 Reply Last reply Reply Quote 0
            • scottalanmillerS
              scottalanmiller @Kelly
              last edited by

              @Kelly said in Is It Really Encrypted When the Key Is Public and Automatic?:

              @DustinB3403 said in Is It Really Encrypted When the Key Is Public and Automatic?:

              @Kelly said in Is It Really Encrypted When the Key Is Public and Automatic?:

              In the state of Colorado the law is written such that if an encryption key is obtained the data is considered compromised.

              Obtained by whom? The customers, the vendors, someone else?

              Does that mean if the rightful customer has the key, that they must consider their system compromised even though they should have the key?

              It is a privacy law. If someone who is not authorized has both the data and the key the data is considered to have been exposed and the company is liable under HB11-1828. If the key is public then any access to the data would be considered a breach and exposure.

              What if it was non-encrypted data, so that there was no key? Wouldn't that be the normal boat, and that's not an exposure.

              1 Reply Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller
                last edited by

                The issue in this case is that the data is not required to be encrypted. But it's sold as a benefit. But it isn't like a HIPAA violation.

                KellyK 1 Reply Last reply Reply Quote 0
                • ObsolesceO
                  Obsolesce @scottalanmiller
                  last edited by

                  @scottalanmiller said in Is It Really Encrypted When the Key Is Public and Automatic?:

                  @Obsolesce said in Is It Really Encrypted When the Key Is Public and Automatic?:

                  False advertisement maybe at best IMO.

                  At best? Isn't giving YOUR keys away to other people fall under hacking laws? It's definitely not legal for them to keep, let alone distribute, your key.

                  Dunno. I'm not a lawyer specializing in privacy and data protection laws. I can only speculate based on general logic. I have no idea about their eula/tos/etc either.

                  DustinB3403D scottalanmillerS 3 Replies Last reply Reply Quote 0
                  • KellyK
                    Kelly @scottalanmiller
                    last edited by

                    @scottalanmiller said in Is It Really Encrypted When the Key Is Public and Automatic?:

                    The issue in this case is that the data is not required to be encrypted. But it's sold as a benefit. But it isn't like a HIPAA violation.

                    So, the Colorado law and some other state laws (may include CCPA) are mandating that certain PII data be encrypted. HB11-1824 has very few teeth to it at this point until someone gets breached, but I don't want to be the test case for the DA to try it out on.

                    1 Reply Last reply Reply Quote 0
                    • DustinB3403D
                      DustinB3403 @Obsolesce
                      last edited by

                      @Obsolesce said in Is It Really Encrypted When the Key Is Public and Automatic?:

                      @scottalanmiller said in Is It Really Encrypted When the Key Is Public and Automatic?:

                      @Obsolesce said in Is It Really Encrypted When the Key Is Public and Automatic?:

                      False advertisement maybe at best IMO.

                      At best? Isn't giving YOUR keys away to other people fall under hacking laws? It's definitely not legal for them to keep, let alone distribute, your key.

                      Dunno. I'm not a lawyer specializing in privacy and data protection laws. I can only speculate based on general logic. I have no idea about their eula/tos/etc either.

                      Most lawyers shouldn't be the expert either. .

                      1 Reply Last reply Reply Quote -1
                      • scottalanmillerS
                        scottalanmiller @Obsolesce
                        last edited by

                        @Obsolesce said in Is It Really Encrypted When the Key Is Public and Automatic?:

                        @scottalanmiller said in Is It Really Encrypted When the Key Is Public and Automatic?:

                        @Obsolesce said in Is It Really Encrypted When the Key Is Public and Automatic?:

                        False advertisement maybe at best IMO.

                        At best? Isn't giving YOUR keys away to other people fall under hacking laws? It's definitely not legal for them to keep, let alone distribute, your key.

                        Dunno. I'm not a lawyer specializing in privacy and data protection laws. I can only speculate based on general logic. I have no idea about their eula/tos/etc either.

                        General logic would say that selling someone a key based on a promise to protect them, then selling that same key to someone else to undermine the security that they just sold to you, is not just a civil problem, but a criminal one. Selling access to other peoples' data is highly illegal.

                        1 Reply Last reply Reply Quote 0
                        • scottalanmillerS
                          scottalanmiller @Obsolesce
                          last edited by

                          @Obsolesce imagine if you were a lock smith, and you sold someone a lock and key. And you told them about the strength of the key and promoted the lock as being so tough to break into. And then secretly made a kept a copy of that key, and then sold those copies to other people!

                          If you were a locksmith, everyone would demand you go to jail, of course. Exactly the same here.

                          ObsolesceO 1 Reply Last reply Reply Quote 0
                          • ObsolesceO
                            Obsolesce @scottalanmiller
                            last edited by

                            @scottalanmiller said in Is It Really Encrypted When the Key Is Public and Automatic?:

                            @Obsolesce imagine if you were a lock smith, and you sold someone a lock and key. And you told them about the strength of the key and promoted the lock as being so tough to break into. And then secretly made a kept a copy of that key, and then sold those copies to other people!

                            If you were a locksmith, everyone would demand you go to jail, of course. Exactly the same here.

                            Sure, that sounds illegal to me... but again, I don't know exactly what they are claiming to do, actually doing, selling, tos/eula/etc.

                            scottalanmillerS 1 Reply Last reply Reply Quote 0
                            • scottalanmillerS
                              scottalanmiller @Obsolesce
                              last edited by

                              @Obsolesce said in Is It Really Encrypted When the Key Is Public and Automatic?:

                              @scottalanmiller said in Is It Really Encrypted When the Key Is Public and Automatic?:

                              @Obsolesce imagine if you were a lock smith, and you sold someone a lock and key. And you told them about the strength of the key and promoted the lock as being so tough to break into. And then secretly made a kept a copy of that key, and then sold those copies to other people!

                              If you were a locksmith, everyone would demand you go to jail, of course. Exactly the same here.

                              Sure, that sounds illegal to me... but again, I don't know exactly what they are claiming to do, actually doing, selling, tos/eula/etc.

                              They are selling their system as described: they are promoting the customer's data as being encrypted. Then selling that same encryption key to their competitors.

                              DustinB3403D 1 Reply Last reply Reply Quote 0
                              • J
                                JasGot
                                last edited by

                                My thoughts.

                                Legally, the data is encrypted and can be advertised as such. No laws broken.

                                Now, here is where you can go after the vendor, with a single word: "Negligence."

                                The vendor will be found profoundly negligent in the way they designed their software.

                                scottalanmillerS 2 Replies Last reply Reply Quote 1
                                • DustinB3403D
                                  DustinB3403 @scottalanmiller
                                  last edited by

                                  @scottalanmiller said in Is It Really Encrypted When the Key Is Public and Automatic?:

                                  @Obsolesce said in Is It Really Encrypted When the Key Is Public and Automatic?:

                                  @scottalanmiller said in Is It Really Encrypted When the Key Is Public and Automatic?:

                                  @Obsolesce imagine if you were a lock smith, and you sold someone a lock and key. And you told them about the strength of the key and promoted the lock as being so tough to break into. And then secretly made a kept a copy of that key, and then sold those copies to other people!

                                  If you were a locksmith, everyone would demand you go to jail, of course. Exactly the same here.

                                  Sure, that sounds illegal to me... but again, I don't know exactly what they are claiming to do, actually doing, selling, tos/eula/etc.

                                  They are selling their system as described: they are promoting the customer's data as being encrypted. Then selling that same encryption key to their competitors.

                                  It's all still encrypted, just with a horribly thought out process for encryption.

                                  scottalanmillerS 1 Reply Last reply Reply Quote 0
                                  • scottalanmillerS
                                    scottalanmiller @DustinB3403
                                    last edited by

                                    @DustinB3403 said in Is It Really Encrypted When the Key Is Public and Automatic?:

                                    @scottalanmiller said in Is It Really Encrypted When the Key Is Public and Automatic?:

                                    @Obsolesce said in Is It Really Encrypted When the Key Is Public and Automatic?:

                                    @scottalanmiller said in Is It Really Encrypted When the Key Is Public and Automatic?:

                                    @Obsolesce imagine if you were a lock smith, and you sold someone a lock and key. And you told them about the strength of the key and promoted the lock as being so tough to break into. And then secretly made a kept a copy of that key, and then sold those copies to other people!

                                    If you were a locksmith, everyone would demand you go to jail, of course. Exactly the same here.

                                    Sure, that sounds illegal to me... but again, I don't know exactly what they are claiming to do, actually doing, selling, tos/eula/etc.

                                    They are selling their system as described: they are promoting the customer's data as being encrypted. Then selling that same encryption key to their competitors.

                                    It's all still encrypted, just with a horribly thought out process for encryption.

                                    It is, but the key is stored with it. If you weld a key in a lock, it becomes a door knob. That's the scenario here, there is never a time that the data is encrypted without the ability to read it.

                                    DashrenderD 1 Reply Last reply Reply Quote 0
                                    • scottalanmillerS
                                      scottalanmiller @JasGot
                                      last edited by

                                      @JasGot said in Is It Really Encrypted When the Key Is Public and Automatic?:

                                      Legally, the data is encrypted and can be advertised as such. No laws broken.

                                      Is this true? In no other context would this be legal. Using "encryption" to refer to something that requires nothing secret to read has never been legal. If it was, you could use it to refer to all data, because everything has to be encoded to be on a computer. Whether it is stored in ASCII or in a file system or XML, that's all encryption by that definition. That's all that it is here, just a weird format but one that involves zero security.

                                      If you pulled that with HIPAA it would be black and white lying about the encryption. Why would this case be different than all other legal cases? What makes this special?

                                      DashrenderD 1 Reply Last reply Reply Quote 0
                                      • scottalanmillerS
                                        scottalanmiller @JasGot
                                        last edited by

                                        @JasGot said in Is It Really Encrypted When the Key Is Public and Automatic?:

                                        Legally, the data is encrypted and can be advertised as such. No laws broken.

                                        If a system uses a password, but enters the password automatically and never asks for it, is it still a password? In this case, uses never need the key to use the data... not even other users. The key is always presented automatically even if you separate the key from the data. The encoding is like ASCII, not like what the IT industry calls encryption.

                                        1 Reply Last reply Reply Quote 0
                                        • DashrenderD
                                          Dashrender @scottalanmiller
                                          last edited by

                                          @scottalanmiller said in Is It Really Encrypted When the Key Is Public and Automatic?:

                                          @JasGot said in Is It Really Encrypted When the Key Is Public and Automatic?:

                                          Legally, the data is encrypted and can be advertised as such. No laws broken.

                                          Is this true? In no other context would this be legal. Using "encryption" to refer to something that requires nothing secret to read has never been legal.

                                          flip that on its ear - has it been specifically illegal? I'm guessing not.

                                          scottalanmillerS 1 Reply Last reply Reply Quote 0
                                          • DashrenderD
                                            Dashrender @scottalanmiller
                                            last edited by

                                            @scottalanmiller said in Is It Really Encrypted When the Key Is Public and Automatic?:

                                            @DustinB3403 said in Is It Really Encrypted When the Key Is Public and Automatic?:

                                            @scottalanmiller said in Is It Really Encrypted When the Key Is Public and Automatic?:

                                            @Obsolesce said in Is It Really Encrypted When the Key Is Public and Automatic?:

                                            @scottalanmiller said in Is It Really Encrypted When the Key Is Public and Automatic?:

                                            @Obsolesce imagine if you were a lock smith, and you sold someone a lock and key. And you told them about the strength of the key and promoted the lock as being so tough to break into. And then secretly made a kept a copy of that key, and then sold those copies to other people!

                                            If you were a locksmith, everyone would demand you go to jail, of course. Exactly the same here.

                                            Sure, that sounds illegal to me... but again, I don't know exactly what they are claiming to do, actually doing, selling, tos/eula/etc.

                                            They are selling their system as described: they are promoting the customer's data as being encrypted. Then selling that same encryption key to their competitors.

                                            It's all still encrypted, just with a horribly thought out process for encryption.

                                            It is, but the key is stored with it. If you weld a key in a lock, it becomes a door knob. That's the scenario here, there is never a time that the data is encrypted without the ability to read it.

                                            I think this is the closest analogy you've put forth so far - but welding is a bit to far, I simply think saying "leave the key in the lock" Because in that case, the key can be removed - just like the key can be removed from the local computer - doesn't matter than others have copies, or can get copies...

                                            so run it from there - what are the legal liabilities?

                                            scottalanmillerS 2 Replies Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 2 / 3
                                            • First post
                                              Last post