Feeds

India issues red alert against US security software

US crypto export rules mean their software isn't safe, warns Defence organisation

  • alert
  • submit to reddit

Internet Security Threat Report 2014

The Indian government looks set to forbid Indian banks and financial institutions from using US-developed network security software if the US government does not ease the restrictions it applies to the export of encryption technologies. The announcement was made by India's Central Vigilance Commissioner (CVC), N Vittal, after the country's Defence Research and Development Organisation's (DRDO) centre for artificial intelligence issued a 'red alert' against all network security software developed in the US. The alert warned that, because of the limits the US government places on the size of data encryption keys in exported applications, US software was too easy to hack and could thus prove a security hazard. "To put it bluntly, only insecure software can be exported. When various multinational companies go around peddling 'secure communication software' products to gullible Indian customers, the conveniently neglect to mention this aspect of US export law," said the DRDO in a letter to the CVC, quoted in Indian newspaper The Economic Times. The DRDO's centre for artificial intelligence also warned of the possibility that imported software products could contain technological time bombs designed to "cause havoc to the network when an external command is issued by a hostile nation". Of course, quite how seriously the DRDO takes such a threat is hard to determine, since its red alert letter appears to be as much about promoting its own, indigenously developed encryption software, which is due to me made available for testing in three months' time. "The encryption part of the software is complete and only the communication protocols remain to be written," reported the DRDO. "Since the software has been written by ourselves, there is no upper limit on the security level provided by encryption in the software exported from the USA." Which is, of course, the fundamental flaw with US encryption policy, despite the Department of Commerce's recent relaxation of some of the rules contained in that policy. If user can't get the level of security they want from US software, they'll go elsewhere for it. And India is less likely to limit the export of its own encryption products to other, unsavoury regimes -- though there's no guarantee they wouldn't include their own 'time bombs'... In the meantime, the CVC is expected to wait until the DRDO's own software is ready before issuing an official warning against US security software to India's banks. ®

Providing a secure and efficient Helpdesk

More from The Register

next story
Scrapping the Human Rights Act: What about privacy and freedom of expression?
Justice minister's attack to destroy ability to challenge state
WHY did Sunday Mirror stoop to slurping selfies for smut sting?
Tabloid splashes, MP resigns - but there's a BIG copyright issue here
Google hits back at 'Dear Rupert' over search dominance claims
Choc Factory sniffs: 'We're not pirate-lovers - also, you publish The Sun'
EU to accuse Ireland of giving Apple an overly peachy tax deal – report
Probe expected to say single-digit rate was unlawful
Inequality increasing? BOLLOCKS! You heard me: 'Screw the 1%'
There's morality and then there's economics ...
Hey Brit taxpayers. You just spent £4m on Central London ‘innovation playground’
Catapult me a Mojito, I feel an Digital Innovation coming on
While you queued for an iPhone 6, Apple's Cook sold shares worth $35m
Right before the stock took a 3.8% dive amid bent and broken mobe drama
EU probes Google’s Android omerta again: Talk now, or else
Spill those Android secrets, or we’ll fine you
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
The next step in data security
With recent increased privacy concerns and computers becoming more powerful, the chance of hackers being able to crack smaller-sized RSA keys increases.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.