Twitter reportedly drops plan to encrypt direct messages

End-to-end encryption is widely considered the best defense against a surveillance dragnet, but the tech companies that many of us interact with on a daily basisFacebook, Google, Twitterhave been slow to offer protections for users. The Verge reported Wednesday that Twitter, which had reportedly planned to encrypt direct messages, has dropped the project to focus on more pressing matters.

Twitter's been working on improvements to direct messages, but encryption fell by the wayside.

It isnt that Twitter doesnt believe in encryption, according to The Verge. Its just that the 7-year-old micro-blogging site has a lot more to accomplish in the near-term: like satisfying shareholders, who are slightly concerned that Twitters growth has stagnated. As The Verge notes, Twitter has a reputation for bucking the establishment. It was one of the few tech companies that declined to participate in the National Security Agencys PRISM surveillance program, and regularly fights government requests for user data. Twitter may still roll out encryption for DMs when it's done simplifying its own product to entice new users.

But the news will come as a disappointment to security watchdogs pushing companies like Twitter, Facebook, and Google to step up their privacy protection efforts.

End-to-end encryption is one of those tech buzz phrases that the average Internet user hasnt pondered too deeply until recently, when it became clear that the NSA is digging into your email, chats, and social networking activities. Edward Snowden appeared at South by Southwest Interactive to encourage tech companies to employ end-to-end encryption for their users, but dont expect major security overhauls anytime soon.

Facebook, Yahoo, Google, and the like use SSL encryption, which is simpler to use than end-to-end but doesnt go as far to protect your information. When you send an email using Yahoo, for instance, the message is encrypted on your end but then decrypted on Yahoos server before being sent along to your intended recipient. End-to-end encryption means the message would remain encrypted on Yahoos server, too.

But end-to-end encryption software isnt easy to use, as the Washington Post broke down in the wake of Snowdens early revelations, and little headway has been made to simplify the process. Until the day comes when you dont have to exchange public keys, a secure means of identity verification, to chat with people, dont expect social networks to offer full message encryption.

Read this article:
Twitter reportedly drops plan to encrypt direct messages

Facebook holds back on end-to-end encryption

News

By Zach Miners

March 19, 2014 05:58 AM ET

IDG News Service - If you're a Facebook user and you want the best form of encryption to keep hackers and spies out of your posts and chats, you don't have a ton of options now.

Facebook has gradually amped up its security protocols and encryption methods over the years. This includes its "bug bounty" program that pays outsiders to uncover security holes, as well as HTTPS encryption, which encrypts people's communications in transit but still decrypts it at data centers before re-encrypting it.

However, end-to-end encryption, which holds promise as the best way to secure users' posts, is not in any of Facebook's major products by default. The technology is meant to encrypt people's communications at their client devices so that governments and others must target the person and not Facebook's data centers.

Facebook has been able to deploy end-to-end encryption for a long time, Chief Security Officer Joe Sullivan said on Tuesday. It hasn't rolled the technology out across its services partly due to its complexity. The company has also held back because, when end-to-end encryption is done right, it's hard for the average person to communicate, he said.

"If you use end-to-end encryption on email, you realize how hard it can be," Sullivan said during a talk with the press at Facebook's headquarters in Menlo Park, California. End-to-end encryption can be hard for people to use and understand because it typically requires a manual process of exchanging public keys between the sender and receiver whenever they send an email or any other type of message.

If Facebook users want that type of security, there are some third-party apps they can use to add end-to-end encryption to Facebook's services, Sullivan said.

Continued here:
Facebook holds back on end-to-end encryption

For Facebook, delivering the strongest security would be a challenge

If you're a Facebook user and you want the best form of encryption to keep hackers and spies out of your posts and chats, you don't have a ton of options now.

Facebook has gradually amped up its security protocols and encryption methods over the years. This includes its "bug bounty" program that pays outsiders to uncover security holes, as well as HTTPS encryption, which encrypts people's communications in transit but still decrypts it at data centers before re-encrypting it.

However, end-to-end encryption, which holds promise as the best way to secure users' posts, is not in any of Facebook's major products by default. The technology is meant to encrypt people's communications at their client devices so that governments and others must target the person and not Facebook's data centers.

IDG News Service - If you're a Facebook user and you want the best form of encryption to keep hackers and spies out of your posts and chats, you don't have a ton of options now.

Facebook has gradually amped up its security protocols and encryption methods over the years. This includes its "bug bounty" program that pays outsiders to uncover security holes, as well as HTTPS encryption, which encrypts people's communications in transit but still decrypts it at data centers before re-encrypting it.

However, end-to-end encryption, which holds promise as the best way to secure users' posts, is not in any of Facebook's major products by default. The technology is meant to encrypt people's communications at their client devices so that governments and others must target the person and not Facebook's data centers.

Facebook has been able to deploy end-to-end encryption for a long time, Chief Security Officer Joe Sullivan said on Tuesday. It hasn't rolled the technology out across its services partly due to its complexity. The company has also held back because, when end-to-end encryption is done right, it's hard for the average person to communicate, he said.

"If you use end-to-end encryption on email, you realize how hard it can be," Sullivan said during a talk with the press at Facebook's headquarters in Menlo Park, California. End-to-end encryption can be hard for people to use and understand because it typically requires a manual process of exchanging public keys between the sender and receiver whenever they send an email or any other type of message.

If Facebook users want that type of security, there are some third-party apps they can use to add end-to-end encryption to Facebook's services, Sullivan said.

Facebook has tried to support end-to-end encryption as a concept, Sullivan said. "At a minimum, we want to support third-party initiatives," he said.

See the original post here:
For Facebook, delivering the strongest security would be a challenge

Keys to the castle: Encryption in the cloud

''We need to be cautious that, similar to the promises of PKI several years ago, the market is ready and the technology robust enough to service client demands'

In a bid to reassure customers following revelations of government intelligence agency snooping in 2013, cloud service providers including Google and Amazon have rushed out free automatic server-side encryption on their cloud services - and not before time.

The move has been seen by many as a positive one for companies that are mandated to protect customer data when running a business application on Google, but it could equally be argued that encouraging them to leave encryption in the hands of the cloud provider is a step in the wrong direction.

While it's obvious that Google and others are covering their own backs and jumping on the marketing opportunity of NSA-related paranoia by having these security processes in place, it's not exactly clear just how adequate their server-side measures are.

After announcing in August last year that it would be automatically encrypting all data on its cloud storage platform before it is written to disk, Google added that it would still advise data to be encrypted at the user end for those who prefer to manage their own encryption keys, emphasising that the responsibility for risk management still legally lies with the customer.

Jamal Elmellas, technical director at data security specialist Auriga, strongly advises that organisations should be wary from the outset of cloud providers with proprietary encryption software and mechanisms, especially those that retro-fit encryption to their already established solutions.

Encryption should be intrinsic to the solution, says Elmellas. It should be considered from the outset by the provider, and this enables them to offer a solution which applies the most appropriate type of encryption to the right parts of the infrastructure.

Processes, logging, auditing and total involvement by the customer are a few of the ways that risks can be minimised when outsourcing encryption, but for companies handling sensitive data, encrypting everything themselves may seem like the safest bet.

However, as Elmallas explains, this option opens up a whole new complex set of considerations.

Read this article:
Keys to the castle: Encryption in the cloud