The European Agency for Network and Information Security (ENISA) has released a document to debunk the myth that encryption at the backdoors is the best way to protect against terrorist acts.
For several years now, government agencies have been asking regulators to write and pass laws that allow them to require companies to provide them with the decryption keys for encrypted data or even force businesses to include a backdoor so they can easily access it whenever needed.
The pressure has increased tenfold since the terrorist attacks in Paris last year, even though there was no evidence that the terrorists planned and carried out the attack using encrypted communications.
With fear running high in Europe, and governments getting tougher on encryption backdoors, EU IT security experts from ENISA are now trying to calm everyone down.
In their paper released last Friday, ENISA provides a simple, well-formulated explanation for why encrypted backdoors may be the worst idea EU regulators may be willing to implement in continent-wide legislation.
ENISA agreed that having encryption on backdoors could help authorities during their investigations, but having encryption key recovery systems and escrow systems has its drawbacks.
First of all, it will be expensive to implement across all organizations, a cost some countries may not be willing to spend if they knew they were also introducing vulnerabilities to their state's security
ENISA explains that key recovery and escrow systems come with their own vulnerabilities, in addition to those of the encryption protocol.
Authorities insist that encryption backdoors do nothing more than increase the attack surface on encrypted communications, providing more weaknesses for attackers to target.
“Key escrow and recovery are theoretically possible, but it would require a radical change to our communications infrastructure and the joint development effort of many experts,” ENISA concluded. “The resulting infrastructure would be more complex, potentially making it more vulnerable to attacks and less resilient to failures. The economic impact could be undesirable.”
Furthermore, ENISA explains that an exposed escrow system is impossible to detect. If an attacker uses the same backdoor encryption as the authorities, no one would ever be able to detect it.
Of course, banning encryption altogether is an even sillier idea, ENISA adds, given that it is technically impossible to implement.

