A group of academic researchers have developed practical attacks targeting two widely used end-to-end encryption schemes for email, which could lead to man-in-the-middle decryption attacks and exfiltration of private keys.
The EARN IT Act would create a flood of state laws regulating Internet use and curtail the use of encrypted services, Sen. Ron Wyden says.
Mozilla will reduce the valid lifespan of TLS certificates in its root store to 398 days in a move to limit exposure for keys and certificates.
The Lawful Access to Encrypted Data Act introduced this week would require device makers and service providers to create exceptional access to encrypted data at rest and in motion.
Protecting data while in use is a challenge. IBM released an open source toolkit to help developers implement fully homomorphic encryption in their applciations.