ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Is It Really Encrypted When the Key Is Public and Automatic?

    Scheduled Pinned Locked Moved IT Discussion
    encryptionsoftwarelegal
    59 Posts 9 Posters 6.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • scottalanmillerS
      scottalanmiller @Obsolesce
      last edited by

      @Obsolesce said in Is It Really Encrypted When the Key Is Public and Automatic?:

      False advertisement maybe at best IMO.

      At best? Isn't giving YOUR keys away to other people fall under hacking laws? It's definitely not legal for them to keep, let alone distribute, your key.

      ObsolesceO 1 Reply Last reply Reply Quote 0
      • scottalanmillerS
        scottalanmiller @Obsolesce
        last edited by

        @Obsolesce said in Is It Really Encrypted When the Key Is Public and Automatic?:

        False advertisement maybe at best IMO.

        Imagine if a company sold you a secure VPN solution. Then publicly gave away your key so that anyone could hack into your communications. That would be a crime.

        DustinB3403D 1 Reply Last reply Reply Quote 0
        • F
          flaxking
          last edited by

          Another reason is ignorance. Thinking that's 'secure enough' without adding additional complexity to deployments.

          1 Reply Last reply Reply Quote 0
          • DustinB3403D
            DustinB3403 @scottalanmiller
            last edited by

            @scottalanmiller said in Is It Really Encrypted When the Key Is Public and Automatic?:

            @Obsolesce said in Is It Really Encrypted When the Key Is Public and Automatic?:

            False advertisement maybe at best IMO.

            Imagine if a company sold you a secure VPN solution. Then publicly gave away your key so that anyone could hack into your communications. That would be a crime.

            You mean like NordVPN losing their private keys?

            scottalanmillerS 1 Reply Last reply Reply Quote 0
            • F
              flaxking
              last edited by

              It's a bad sign when questions about security from your clients have to go through your lawyer every time.

              scottalanmillerS 1 Reply Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller @DustinB3403
                last edited by

                @DustinB3403 said in Is It Really Encrypted When the Key Is Public and Automatic?:

                @scottalanmiller said in Is It Really Encrypted When the Key Is Public and Automatic?:

                @Obsolesce said in Is It Really Encrypted When the Key Is Public and Automatic?:

                False advertisement maybe at best IMO.

                Imagine if a company sold you a secure VPN solution. Then publicly gave away your key so that anyone could hack into your communications. That would be a crime.

                You mean like NordVPN losing their private keys?

                Losing isn't the same as giving away knowingly.

                1 Reply Last reply Reply Quote 0
                • scottalanmillerS
                  scottalanmiller @flaxking
                  last edited by

                  @flaxking said in Is It Really Encrypted When the Key Is Public and Automatic?:

                  It's a bad sign when questions about security from your clients have to go through your lawyer every time.

                  Sadly, if their customers try to access their own data the vendor sues them. They claim that the customers don't have the right to use the public keys that they give away.

                  DashrenderD 1 Reply Last reply Reply Quote 0
                  • DashrenderD
                    Dashrender @scottalanmiller
                    last edited by

                    @scottalanmiller said in Is It Really Encrypted When the Key Is Public and Automatic?:

                    @flaxking said in Is It Really Encrypted When the Key Is Public and Automatic?:

                    It's a bad sign when questions about security from your clients have to go through your lawyer every time.

                    Sadly, if their customers try to access their own data the vendor sues them. They claim that the customers don't have the right to use the public keys that they give away.

                    You client is running into that issue now?

                    and how did the vendor find out?

                    scottalanmillerS 1 Reply Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller @Dashrender
                      last edited by

                      @Dashrender said in Is It Really Encrypted When the Key Is Public and Automatic?:

                      @scottalanmiller said in Is It Really Encrypted When the Key Is Public and Automatic?:

                      @flaxking said in Is It Really Encrypted When the Key Is Public and Automatic?:

                      It's a bad sign when questions about security from your clients have to go through your lawyer every time.

                      Sadly, if their customers try to access their own data the vendor sues them. They claim that the customers don't have the right to use the public keys that they give away.

                      You client is running into that issue now?

                      and how did the vendor find out?

                      We know a client that is having this issue. He posts about it. They found out because he let others know how to access their own data and exposed that the encryption wasn't unique: that they all shared a single key.

                      The knowledge can be used, obviously, to sue the vendor out of existence (and it ties back to EMR stuff, so while this one key isn't HIPAA related, the company is) and can be used to migrate customer data off of their platforms (the real reason that they are trying to encrypt the data - to extort the customers for migration fees.)

                      1 Reply Last reply Reply Quote 0
                      • scottalanmillerS
                        scottalanmiller
                        last edited by

                        So in this case, while not nearly as bad as most, it's actually ransonware, right?

                        DashrenderD 1 Reply Last reply Reply Quote 0
                        • G I JonesG
                          G I Jones
                          last edited by

                          In this case would the definition of "encryption" be relevant? It's pretty vague as is. This is super fucked at any rate. I hope all the bad things in life happen to that company and only that company.

                          scottalanmillerS 1 Reply Last reply Reply Quote 1
                          • scottalanmillerS
                            scottalanmiller @G I Jones
                            last edited by

                            @G-I-Jones said in Is It Really Encrypted When the Key Is Public and Automatic?:

                            In this case would the definition of "encryption" be relevant? It's pretty vague as is. This is super fucked at any rate. I hope all the bad things in life happen to that company and only that company.

                            I think it does because the Fed defines encryption in all kinds of things like HIPAA.

                            1 Reply Last reply Reply Quote 0
                            • DashrenderD
                              Dashrender @scottalanmiller
                              last edited by

                              @scottalanmiller said in Is It Really Encrypted When the Key Is Public and Automatic?:

                              So in this case, while not nearly as bad as most, it's actually ransonware, right?

                              Wouldn't that apply to any system that prevents you from extracting your data, unless you pay a fee?

                              scottalanmillerS 1 Reply Last reply Reply Quote 0
                              • scottalanmillerS
                                scottalanmiller @Dashrender
                                last edited by

                                @Dashrender said in Is It Really Encrypted When the Key Is Public and Automatic?:

                                @scottalanmiller said in Is It Really Encrypted When the Key Is Public and Automatic?:

                                So in this case, while not nearly as bad as most, it's actually ransonware, right?

                                Wouldn't that apply to any system that prevents you from extracting your data, unless you pay a fee?

                                If it does so by maliciously encrypting your data to their benefit, not yours, yes. Generally that's considered illegal. Hence the term "ransomware". It refers to using encryption to make you unable to access your own data so that you have to pay a ransom to get it back.

                                1 Reply Last reply Reply Quote 0
                                • scottalanmillerS
                                  scottalanmiller
                                  last edited by

                                  And, like a lot of ransomware, it also means that someone else has access to your data that you do not.

                                  1 Reply Last reply Reply Quote 0
                                  • KellyK
                                    Kelly
                                    last edited by

                                    In the state of Colorado the law is written such that if an encryption key is obtained the data is considered compromised.

                                    DustinB3403D scottalanmillerS 2 Replies Last reply Reply Quote 1
                                    • DustinB3403D
                                      DustinB3403 @Kelly
                                      last edited by

                                      @Kelly said in Is It Really Encrypted When the Key Is Public and Automatic?:

                                      In the state of Colorado the law is written such that if an encryption key is obtained the data is considered compromised.

                                      Obtained by whom? The customers, the vendors, someone else?

                                      Does that mean if the rightful customer has the key, that they must consider their system compromised even though they should have the key?

                                      KellyK 1 Reply Last reply Reply Quote 0
                                      • scottalanmillerS
                                        scottalanmiller @Kelly
                                        last edited by

                                        @Kelly said in Is It Really Encrypted When the Key Is Public and Automatic?:

                                        In the state of Colorado the law is written such that if an encryption key is obtained the data is considered compromised.

                                        That's the case in most places, I think, but good to know as we have loads of people in CO with this.

                                        1 Reply Last reply Reply Quote 0
                                        • KellyK
                                          Kelly @DustinB3403
                                          last edited by

                                          @DustinB3403 said in Is It Really Encrypted When the Key Is Public and Automatic?:

                                          @Kelly said in Is It Really Encrypted When the Key Is Public and Automatic?:

                                          In the state of Colorado the law is written such that if an encryption key is obtained the data is considered compromised.

                                          Obtained by whom? The customers, the vendors, someone else?

                                          Does that mean if the rightful customer has the key, that they must consider their system compromised even though they should have the key?

                                          It is a privacy law. If someone who is not authorized has both the data and the key the data is considered to have been exposed and the company is liable under HB11-1828. If the key is public then any access to the data would be considered a breach and exposure.

                                          DustinB3403D scottalanmillerS 2 Replies Last reply Reply Quote 0
                                          • DustinB3403D
                                            DustinB3403 @Kelly
                                            last edited by

                                            @Kelly said in Is It Really Encrypted When the Key Is Public and Automatic?:

                                            not authorized

                                            Gotcha, so it's not a poorly written law but only applies in the case of not authorized cases.

                                            KellyK 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 1 / 3
                                            • First post
                                              Last post