Re: Draft IP-Bill enters wrap-up phase

Adrian Midgley <[email protected]> Tue, 26 Jan 2016 14:26:36 +0000
Newsgroups gmane.law.cryptography.uk
Message-ID <CAN2jWyj9E_AvKR6OPJ4ywbKMs1BJkoLwsWcx6sn71HG9C8qs6g@mail.gmail.com>
--001a11c28252b3023d052a3d79a3
Content-Type: text/plain; charset=UTF-8

> By default private internets are no more secure than the public one.

An inconvenient truth within the NHS.

On Tue, 26 Jan 2016, 12:24 Dave Howe <[email protected]> wrote:

> On 24/01/2016 17:56, Roger Hayter wrote:
>
> > I was never important enough to be advised to do such a thing. It
> > does seem remarkably simple, but raises more questions.  Does it use
> > the same SSL libraries as used for encrypted web sites?
>
>   Yes, mostly. Generation will use the SSL library of your web browser,
> usage the SSL library of your email client. Underlying protocol is the
> same.
>
> > If Thawte issue a certificate which you then use, does this
> > potentially give them a way into your encrypted information or not?
>
>   Not - just as Thawte issuing a cert for your webserver doesn't give
> them a way to reach that traffic. The private key is generated locally
> by your web browser and never leaves your machine.
>
>
> > And is this the same system the English NHS use for end-to-end
> > encryption?
>
>   Yes
>
> > It would seem to render NHSnet irrelevant, unless its sole role is
> > to prevent you sending encrypted email or secret documents outside
> > NHSnet.
>
>   No. NHSnet/CfH/whatevertheyarecallingitthisweek isn't actually
> encrypted - it's a private internet, with access controls, but any
> security has to be layered onto that or traffic will be available to the
> BT engineers who maintain and support it. As always, HTTPS & SMTPS can
> protect point-to-point links, but S/MIME is recommended to protect data
> end-to-end. By default private internets are no more secure than the
> public one.
>
>
>

--001a11c28252b3023d052a3d79a3
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<p dir=3D"ltr">&gt;=C2=A0By default private internets are no more secure th=
an the public one.<br></p>
<p dir=3D"ltr">An inconvenient truth within the NHS.</p>
<br><div class=3D"gmail_quote"><div dir=3D"ltr">On Tue, 26 Jan 2016, 12:24=
=C2=A0Dave Howe &lt;<a href=3D"mailto:[email protected]">daveho=
[email protected]</a>&gt; wrote:<br></div><blockquote class=3D"gmail_=
quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1=
ex">On 24/01/2016 17:56, Roger Hayter wrote:<br>
<br>
&gt; I was never important enough to be advised to do such a thing. It<br>
&gt; does seem remarkably simple, but raises more questions.=C2=A0 Does it =
use<br>
&gt; the same SSL libraries as used for encrypted web sites?<br>
<br>
=C2=A0 Yes, mostly. Generation will use the SSL library of your web browser=
,<br>
usage the SSL library of your email client. Underlying protocol is the same=
.<br>
<br>
&gt; If Thawte issue a certificate which you then use, does this<br>
&gt; potentially give them a way into your encrypted information or not?<br=
>
<br>
=C2=A0 Not - just as Thawte issuing a cert for your webserver doesn&#39;t g=
ive<br>
them a way to reach that traffic. The private key is generated locally<br>
by your web browser and never leaves your machine.<br>
<br>
<br>
&gt; And is this the same system the English NHS use for end-to-end<br>
&gt; encryption?<br>
<br>
=C2=A0 Yes<br>
<br>
&gt; It would seem to render NHSnet irrelevant, unless its sole role is<br>
&gt; to prevent you sending encrypted email or secret documents outside<br>
&gt; NHSnet.<br>
<br>
=C2=A0 No. NHSnet/CfH/whatevertheyarecallingitthisweek isn&#39;t actually<b=
r>
encrypted - it&#39;s a private internet, with access controls, but any<br>
security has to be layered onto that or traffic will be available to the<br=
>
BT engineers who maintain and support it. As always, HTTPS &amp; SMTPS can<=
br>
protect point-to-point links, but S/MIME is recommended to protect data<br>
end-to-end. By default private internets are no more secure than the<br>
public one.<br>
<br>
<br>
</blockquote></div>

--001a11c28252b3023d052a3d79a3--