Feeds

India issues red alert against US security software

US crypto export rules mean their software isn't safe, warns Defence organisation

  • alert
  • submit to reddit

Remote control for virtualized desktops

The Indian government looks set to forbid Indian banks and financial institutions from using US-developed network security software if the US government does not ease the restrictions it applies to the export of encryption technologies. The announcement was made by India's Central Vigilance Commissioner (CVC), N Vittal, after the country's Defence Research and Development Organisation's (DRDO) centre for artificial intelligence issued a 'red alert' against all network security software developed in the US. The alert warned that, because of the limits the US government places on the size of data encryption keys in exported applications, US software was too easy to hack and could thus prove a security hazard. "To put it bluntly, only insecure software can be exported. When various multinational companies go around peddling 'secure communication software' products to gullible Indian customers, the conveniently neglect to mention this aspect of US export law," said the DRDO in a letter to the CVC, quoted in Indian newspaper The Economic Times. The DRDO's centre for artificial intelligence also warned of the possibility that imported software products could contain technological time bombs designed to "cause havoc to the network when an external command is issued by a hostile nation". Of course, quite how seriously the DRDO takes such a threat is hard to determine, since its red alert letter appears to be as much about promoting its own, indigenously developed encryption software, which is due to me made available for testing in three months' time. "The encryption part of the software is complete and only the communication protocols remain to be written," reported the DRDO. "Since the software has been written by ourselves, there is no upper limit on the security level provided by encryption in the software exported from the USA." Which is, of course, the fundamental flaw with US encryption policy, despite the Department of Commerce's recent relaxation of some of the rules contained in that policy. If user can't get the level of security they want from US software, they'll go elsewhere for it. And India is less likely to limit the export of its own encryption products to other, unsavoury regimes -- though there's no guarantee they wouldn't include their own 'time bombs'... In the meantime, the CVC is expected to wait until the DRDO's own software is ready before issuing an official warning against US security software to India's banks. ®

Top 5 reasons to deploy VMware with Tegile

More from The Register

next story
I'll be back (and forward): Hollywood's time travel tribulations
Quick, call the Time Cops to sort out this paradox!
Musicians sue UK.gov over 'zero pay' copyright fix
Everyone else in Europe compensates us - why can't you?
Megaupload overlord Kim Dotcom: The US HAS RADICALISED ME!
Now my lawyers have bailed 'cos I'm 'OFFICIALLY' BROKE
MI6 oversight report on Lee Rigby murder: US web giants offer 'safe haven for TERRORISM'
PM urged to 'prioritise issue' after Facebook hindsight find
BT said to have pulled patent-infringing boxes from DSL network
Take your license demand and stick it in your ASSIA
Right to be forgotten should apply to Google.com too: EU
And hey - no need to tell the website you've de-listed. That'll make it easier ...
prev story

Whitepapers

Go beyond APM with real-time IT operations analytics
How IT operations teams can harness the wealth of wire data already flowing through their environment for real-time operational intelligence.
Why CIOs should rethink endpoint data protection in the age of mobility
Assessing trends in data protection, specifically with respect to mobile devices, BYOD, and remote employees.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Protecting against web application threats using SSL
SSL encryption can protect server‐to‐server communications, client devices, cloud resources, and other endpoints in order to help prevent the risk of data loss and losing customer trust.