{"id":13917,"date":"2021-01-18T07:58:00","date_gmt":"2021-01-18T12:58:00","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=13917"},"modified":"2023-05-24T12:42:19","modified_gmt":"2023-05-24T16:42:19","slug":"all-about-encryption-backdoors","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/all-about-encryption-backdoors\/","title":{"rendered":"All About Encryption Backdoors"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-we-examine-the-double-edged-swords-of-the-cybersecurity-world\">We Examine the Double-Edged Swords of the Cybersecurity World<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s not in your pocket. Not in the car. Not in your bag. Where could your key be? You need a way to get in your place. So, you call a locksmith, who can use his tools to provide another way inside.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But what if we\u2019re talking encryption instead? There are no locksmiths in the cryptography world. What gets encrypted stays encrypted (unless you\u2019re the owner). Theoretically, at least. One exception to that rule is encryption backdoors.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Encryption backdoors are a simple concept. Think of them like the spare key you hide under the rock in your yard. They\u2019re a weakness that allows for entry in case of a loss of access or an emergency. They can be maliciously created by malware or intentionally placed in either hardware or software. There has been much debate about encryption backdoors because the two main sides are viewing the issue from very different perspectives. On one hand, they allow for a way in if the situation requires it. But on the other hand, they can and most likely will be found by attackers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So how do encryption backdoors work exactly? In what circumstances have they been used in the past? And what are the arguments for and against their deployment?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-is-an-encryption-backdoor\">What Is an Encryption Backdoor?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">An encryption backdoor is any method that allows a user (whether authorized or not) to bypass encryption and gain access to a system. Encryption backdoors are similar in theory to vulnerabilities, especially with regards to functionality. Both offer a non-standard way for a user to enter a system as they please. The difference lies in the human train of thought behind them. Encryption backdoors are deliberately put in place, either by software developers or attackers. Vulnerabilities, however, are accidental in nature.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In the world of cyberthreats, backdoors are among the most discreet kind. They\u2019re the polar opposite of something like ransomware, which is the cyber-equivalent of grabbing the user and slapping them in the face repeatedly. Encryption backdoors are well hidden, lurk in the background, and are only known by a very small group of people. Only the developers and a handful of select users that require the capabilities that the backdoor provides should be aware of its existence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The power and versatility of backdoors has made them very popular among cybercriminals. In fact, a <a href=\"https:\/\/resources.malwarebytes.com\/files\/2019\/01\/Malwarebytes-Labs-2019-State-of-Malware-Report-2.pdf\">2019 study by Malwarebytes<\/a> found that backdoors in general, including encryption backdoors, were number four on the list of most common threats faced by both consumers and businesses. The report also discovered that the use of backdoors is on the rise, with a 34% increase in detections for consumers and a whopping 173% increase for businesses, compared to the previous year. Considering encryption backdoors are one of the primary types of backdoors, their use is no doubt on the rise, as well.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s more important than ever to be aware of encryption backdoors and how they work. Since they can be used for either good or evil, it\u2019s not always the most straightforward subject. Let\u2019s look at both sides of the coin by taking a closer at the different ways they are put into practice.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-how-are-encryption-backdoors-used\">How Are Encryption Backdoors Used?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Some backdoors are are intended to help users, and others are intended to hurt them. We\u2019re going to classify backdoors into two primary types based on the result they\u2019re designed to achieve \u2013 malware backdoors and built-in backdoors.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-malware-backdoors\">Malware Backdoors<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">We\u2019ll start with the bad guys first. They create backdoor malware for nefarious means, such as stealing personal data, accessing your financial records, loading additional types of malware onto your system, or completely taking over your device.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Backdoor malware is considered a type of Trojan, which means that it aims to disguise itself as something completely different from its true form. You may think you\u2019re downloading a regular old Word document or a trusted piece of software from a file-sharing site, but you\u2019re actually getting something that\u2019s going to open up a backdoor on your system that an attacker can use to access whenever they want.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Backdoor malware, like Trojans, can also be capable of copying itself and distributing the copies across networks to other systems. They can do this all automatically without any input required from the hacker.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These backdoors can then be used as a means to an end for further attacks, such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Spyware<\/li>\n\n\n\n<li>Keyloggers<\/li>\n\n\n\n<li>Ransomware<\/li>\n\n\n\n<li>Cryptojacking<\/li>\n\n\n\n<li>Using your PC in a <a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-a-ddos-attack\/\">DDOS attack<\/a><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">For instance, maybe you download a free file converter. You go to use it and it doesn\u2019t seem to work properly (spoiler alert \u2013 it was never intended to) so you go and uninstall it from your system. Unbeknownst to you though, the converter was actually backdoor malware, and you now have a wide-open backdoor on your system.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Attackers can go a step further and create a backdoor using a functional piece of software. Perhaps you downloaded a widget that displays regularly updated stock prices. You install it and it works just fine. Nothing seems amiss. But little did you know, it also opened a backdoor on your machine.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For cybercriminals, that\u2019s usually just the first step \u2013getting their foot in the door. A common avenue for hackers to go down at this point is deploying a <a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-a-rootkit-and-how-does-it-work\/\">rootkit<\/a>. The rootkit is a collection of malware that serves to make itself invisible and conceal network activity from you and your PC. Think of a rootkit like a doorstop that keeps the point of access open to the attacker.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Rootkits and backdoor malware in general can be difficult to detect, so be careful when browsing, avoid files from unknown or untrusted sources, keep your applications &amp; OS updated, and take advantage of anti-virus and anti-malware programs.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-built-in-backdoors\">Built-In Backdoors<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s not all bad when it comes to encryption backdoors, however. As we touched on, they can be used for ethical purposes, too. Perhaps a user is locked out of critical information or services and doesn\u2019t have any other way to get in. An encryption backdoor can restore access. They can also be of help when troubleshooting software issues, or even be used to access information that can help solve crimes or find a missing person or object.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Built-in backdoors are purposely deployed by hardware and software developers, and they aren\u2019t usually created with nefarious means in mind. Oftentimes they\u2019re simply part of the development process. Backdoors are used by developers so they can more easily navigate the applications as they\u2019re coding, testing, and fixing bugs. Without a backdoor, they\u2019d have to jump through more hoops like creating a \u201creal\u201d account, entering personal information that\u2019s usually required for regular users, confirming their email address, etc.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Backdoors like these aren\u2019t meant to be part of the final product, but sometimes they get left in by accident. As with a vulnerability, there\u2019s a chance that the backdoor will be discovered and used by attackers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The other main category of built-in backdoors is those that are requested by national governments and intelligence agencies. The governments of the Five Eyes (FVEY) intelligence alliance, Australia, Canada, New Zealand, the United Kingdom, and the United States, have repeatedly requested that tech and software companies install backdoors in their products. Their rationale is that these backdoors can help find critical evidence for use in criminal investigations. Apple, Facebook, and Google have all said no to these requests.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If a company does agree to installing a backdoor however, then it usually happens somewhere in the supply chain, where it is appropriately referred to as a \u201csupply chain backdoor.\u201d&nbsp; It\u2019s because it occurs during the manufacturing and\/or development process when the components of the product are still floating around at some point in the supply chain. For instance, a backdoor could be loaded onto a microprocessor at the chip maker\u2019s facility, whereafter it gets sent to various OEMs for use in consumer products. Or it could be loaded as the finished product is being sent to the consumer. For example, a government agency could intercept a shipment of devices meant for an end-user and load a backdoor via a firmware update. Encryption backdoors can be installed with the knowledge of the manufacturer or done covertly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Supply chain backdoors can occur during the software development process, as well. Open-source code has many advantages for developers, saving time and resources instead of reinventing the wheel. Functional and proven libraries, applications, and development tools are created and maintained for the greater good, free for all to use. It has proven to be an efficient and powerful system.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Except, of course, when a backdoor is intentionally planted somewhere. Contributions to open-source code are always subject to review and scrutiny, but there are times when a malicious backdoor can slip through the cracks and make its way out to developers and eventually users. In fact, GitHub found in a 2020 report that nearly <a href=\"https:\/\/www.zdnet.com\/article\/open-source-software-how-many-bugs-are-hidden-there-on-purpose\/\">one in five software bugs were intentionally created for malicious purposes<\/a>.&nbsp;<\/p>\n\n\n<span style=\"--tl-form-height-m:861.156px;--tl-form-height-t:899.625px;--tl-form-height-d:899.625px;\" class=\"tl-placeholder-f-type-shortcode_12653 tl-preload-form\"><span><\/span><\/span>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-encryption-backdoors-in-the-real-world\">Encryption Backdoors in the Real World<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s take a look at some of the most significant and well known instances of encryption backdoors, and the consequences associated with their use:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>1993 \u2013 Clipper Chip<\/strong> \u2013 While there were previous encryption backdoors prior to this, the <a href=\"https:\/\/epic.org\/crypto\/clipper\/\">Clipper Chip of 1993<\/a> was the first to gain major mainstream attention. The chip was an effort by the NSA to create a security system that, while sufficiently secure, could also be cracked at will by investigators if the need arose. The way it worked was that an 80-bit key was burned into the chip as it was manufactured. A copy of that key was held in escrow, and government agents with sufficient clearance could access it. The concept was met with heavy resistance within the industry, never quite got off the ground, and was dead within a few years.<\/li>\n\n\n\n<li><strong>2005 \u2013 Sony BMG<\/strong> \u2013 A decade and a half ago, while you were busy listening to 50 Cent or Mariah Carey, <a href=\"https:\/\/www.networkworld.com\/article\/2998251\/sony-bmg-rootkit-scandal-10-years-later.html\">Sony was shipping millions of CD\u2019s containing a rootkit<\/a>. Intended as a copyright protection measure, it would automatically install itself on your PC when the CD was inserted. Not only did it try and prevent you from burning CDs, but it also spied on your listening habits and opened a backdoor on your machine. Sony faced a wave of lawsuits as a result, recalling the CDs in question and paying out millions in damages.<\/li>\n\n\n\n<li><strong>2013 \u2013 Edward Snowden<\/strong> \u2013 One of the many revelations that came as a result of Snowden\u2019s leaks was that the government had, in numerous instances, <a href=\"https:\/\/www.infoworld.com\/article\/2608141\/snowden--the-nsa-planted-backdoors-in-cisco-products.html\">intercepted network gear en route to an end user and loaded compromised firmware<\/a> on it. The firmware, of course, contained a backdoor that the NSA could (and often did) use to gain access to the user\u2019s network.<\/li>\n\n\n\n<li><strong>2014 <\/strong>\u2013 <strong>Emotet <\/strong>\u2013 A malware strain, and more specifically a banking Trojan, Emotet is essentially an information stealer. It was originally intended for gathering sensitive financial data but is <a href=\"https:\/\/www.blumira.com\/emotet-malware\/\">now used primarily as a backdoor<\/a>. As of 2019, it was still one of the most prevalent threats in cyberspace and is commonly used as a starting point for launching ransomware attacks.<\/li>\n\n\n\n<li><strong>2015 \u2013 Apple <\/strong>\u2013 Apple has continuously refused to put backdoors in their products, despite repeated requests from the US government. The most high-profile instance happened in 2015, following the San Bernardino terrorist attacks. The FBI found an iPhone that was owned by one of the perpetrators and <a href=\"https:\/\/www.blumira.com\/emotet-malware\/\">asked Apple to help unlock it<\/a>. Apple said no and even made a concerted effort to make their devices harder to crack moving forward. The FBI was eventually able to use a third-party to access the phone.<\/li>\n\n\n\n<li><strong>2017 \u2013 WordPress Plugins <\/strong>\u2013 An SEO scam in 2017 <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/backdoor-found-in-wordpress-plugin-with-more-than-300-000-installations\/\">ended up affecting over 300,000 WordPress sites<\/a>, revolving around a WordPress plugin \u201cSimply WordPress.\u201d&nbsp; It was a CAPCHA plugin that did more than advertised, unfortunately. It came with a \u201cfeature\u201d that opened a backdoor that provided admin access to the site it was installed on.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-the-debate-about-encryption-backdoors\">The Debate About Encryption Backdoors<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The debate around the existence of encryption backdoors, and particularly built-in backdoors, has been raging on for decades. Thanks to the \u201cshades of grey\u201d nature of their intended and actual uses, the debate shows no sign of slowing down anytime soon. Especially considering that the main proponent of encryption backdoors, national governments, is also the only party that could legally outlaw them. So, what are the two sides of the argument?<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-the-pros-of-encryption-backdoors\">The Pros of Encryption Backdoors<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The members of the Five Eyes alliance argue that built-in encryption backdoors are a must for maintaining national and global security. Then-FBI Director Christopher Wray attempted to sum up the US government\u2019s position in 2018, explaining<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cWe\u2019re not looking for a &#8216;back door&#8217;\u2014which I understand to mean some type of secret, insecure means of access. What we\u2019re asking for is the ability to access the device once we\u2019ve obtained a warrant from an independent judge, who has said we have probable cause.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Government officials often point out that what they truly desire is more like a \u201cfront door\u201d that can grant access and decryption only in situations that meet certain criteria. The theory is that it would be something only the \u201cgood guys\u201d can use.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Those in favor of backdoors argue that the technological gap between the authorities and cybercriminals is growing, and that the legal and technological powers of law enforcement agencies aren\u2019t currently enough to keep up. Hence, the need for a shortcut, a secret way in.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In other instances, authorities simply need access to gain evidence and information regarding a case. Numerous criminal investigations have been held up because locked phones couldn\u2019t be accessed. And after all, isn\u2019t the information in a phone the kind that police would normally have the right to access with a search warrant?<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-key-escrow-backdoors\">Key Escrow Backdoors<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">A common solution that is proposed by supporters of built-in backdoors is the use of what\u2019s called a \u201ckey escrow\u201d system. The concept is that a trusted third party would act as a secure repository for keys, allowing for decryption if law enforcement can get legal permission to do so.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Key escrow is often used internally by companies in case access to their own data is lost. When it comes to public use though, it\u2019s a system that is challenging and costly to implement. There\u2019s also a large security risk, since all an attacker would need to do to decrypt something is gain access to the key storage location.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-the-cons-of-encryption-backdoors\">The Cons of Encryption Backdoors<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A \u201cfront door\u201d for the good guys sounds great in theory. The problem is, functionally, there isn\u2019t much difference between that and an encryption backdoor. A hacker will be able to find their way in if it exists, no matter what you want to call it. It\u2019s for this reason that most of the big tech companies don\u2019t want encryption backdoors in their products. Because then they will be putting their brand name on insecure products that come with out-of-the-box vulnerabilities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Even if the manufacturer and\/or the government are the only ones to initially know about the backdoor, it\u2019s inevitable that attackers will eventually discover it. On the large scale, a proliferation of backdoors would almost certainly result in an increase of cybercrimes and create a massive black market of exploits. There could be severe and far-reaching impacts for the public-at-large. For instance, utility infrastructure and critical systems could suddenly be left wide open to attacks from threats both at home and abroad.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There is also the question of privacy when it comes to encryption backdoors. If backdoors are everywhere, then suddenly a government can eavesdrop on citizens and view their personal data as they wish. Even if they didn\u2019t at first, the possibility is still there, and it\u2019s a slippery slope that gets more slippery with time. A hostile and immoral government, for example, could use a backdoor to locate dissidents that are speaking out against the regime and silence them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Overall, when it comes to encryption, there\u2019s a few basics that are absolutely required in order for it to be effective:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The data can\u2019t be decrypted without the decryption key<\/li>\n\n\n\n<li>The decryption key can only be accessed by the owner<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Backdoors compromise the second point (and in some cases the first), and in that sense they defeat the entire purpose of encrypting data in the first place.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-the-future-of-encryption-backdoors\">The Future of Encryption Backdoors<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The refusal of the giant technology companies to grant encryption backdoors, particularly Apple\u2019s actions in 2015, has thus far prevented the setting of any legal precedents for backdoors. If any of them had acquiesced, then more encryption backdoors would have no doubt been created moving forward. While encryption backdoors can result in positive outcomes in certain cases, they also come at the price of exposing our devices to greater risk of attack.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These risks are already increasing, independent of backdoors, thanks to the Internet of Things and proliferation of \u201csmart\u201d devices all over our homes and workplaces. An attacker could compromise an IoT device and work their way up the chain of connections to your own PC, and backdoors make it even easier.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In one corner, you have security experts and privacy advocates in favor of maintaining the strongest possible encryption measures and practices. In the opposite corner you have governments that want backdoors to help solve crimes and maintain public safety. The discussion shows no signs of slowing up and will most likely intensify as technology continues to evolve and spread.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Either way, you and I must continue to protect our own data as best we can. We can\u2019t necessarily prevent an attack via a built-in backdoor that we don\u2019t even know exists, but we can employ an intelligent mix of security software and best practices to help mitigate the risk of malware backdoors. &nbsp;Make sure your data is encrypted with an encryption algorithm you trust, and that you have full control over the encryption key. If there\u2019s a possibility that someone else has a key for your data, then it\u2019s not secure.<\/p>\n\n\n<span style=\"--tl-form-height-m:801.312px;--tl-form-height-t:638.344px;--tl-form-height-d:638.344px;\" class=\"tl-placeholder-f-type-shortcode_12763 tl-preload-form\"><span><\/span><\/span>","protected":false},"excerpt":{"rendered":"<p>We Examine the Double-Edged Swords of the Cybersecurity World It\u2019s not in your pocket. Not in the car. Not in your bag. Where could your key be? You need a&#8230;<\/p>\n","protected":false},"author":37,"featured_media":13918,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[130,16],"tags":[],"class_list":["post-13917","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-everything-encryption","category-hashing-out-cyber-security","post-without-tags"],"views":20680,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/01\/bigstock-Rear-View-Man-In-Front-Of-Many-280564654.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/13917","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/37"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=13917"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/13917\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/13918"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=13917"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=13917"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=13917"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}