arise where “acts that might previously have been considered civilian attacks are […] uncovered as
acts of states against states via nonstate actor proxies”.56
Encryption is also an issue. Data can be increasingly stored and sent in an encrypted form. Of
particular note is end-to-end encryption (E2EE), which is becoming increasingly common, if not
quite (yet) the norm.57 With traditional encryption methods, the facilitator—that is, the company,
transmitter or ISP—itself holds the cryptographic key. As a result, anyone compromising the
facilitator’s systems has access to the cryptographic key, and thus to the data of all individual users
relying on the facilitator’s resources. By contrast, E2EE securitizes communications on an individual
basis. E2EE creates two complementary cryptographic keys (rather than one, common key, as is
in traditional encryption). Those keys are with the communicating parties and the communicating
parties alone58: the decryption key (a “private” or “secret” key) never leaves the user’s device,
while the encryption key (a “public” key) can be shared with those sending messages to the user.59
With this protection in place, only those directly communicating can read the messages, thereby
preventing even successful eavesdroppers from understanding the message’s garbled contents.
Successful eavesdroppers would be forced to independently decrypt the data. However, the
possibility of independently decrypting captured E2EE-protected data is increasingly unlikely, as the
possible number of decryption combinations has increased exponentially. Indeed, the possibility of
cracking an encrypted message—typically done through a cryptanalytic attack, known as a bruteforce attack or an exhaustive key search—has become challenging to the point of near-impossibility,
even with sophisticated software.60 Although E2EE is still susceptible to so-called man-in-the-middle
attacks (whereby the interceptor impersonates the recipient, attempting to encrypt the message
with his public key instead of the one intended by the sender), E2EE has substantially reduced the
viability of illegally intercepting data.61 Deciphering by interlopers is made more difficult by features
such as PFS-perfect forward secrecy, which create new encryption keys for each message sent.62
As a result, intercepting data being sent between devices is generally less valuable than being
able to read the data on the device, either before encrypting and sending or after receiving and
decrypting.
Box 1.3: Understanding Encryption
Encryption methods are rendering it increasingly difficult for those intercepting data to
decipher the data.63 For instance, the factorization of a 256-bit AES key64—which the NSA
requires for data classified up to Top Secret, and which is used by many other third-party
providers, including WhatsApp—has 256-bit possible options: that is, any sequence of 256
bits is a potential key, and there is no internal structure to those 256 bits.65
One byte—equivalent to two nibbles or eight bits—can hold 256 different states, possibilities
or values. Each bit has one of two values: 0 or 1. The number combination exponentially
increases the number of potential sequences.
Page 35 | Chapter 1 | § C. Challenges to Fighting Cybercrime
Table of Contents