Insights Topic

Privacy

Browse Attomus insight related to privacy, with a focus on programme delivery, operational judgement, and professional execution in demanding environments.

Topic summary

3 related insights

Use this topic page to move quickly through the most relevant Attomus thinking without losing the wider context across the full insights section.

Metadata: The Half of Privacy That Encryption Doesn't Cover

Michael Hayden – the only person to have run both the NSA and the CIA – told a 2014 debate at Johns Hopkins, “We kill people based on metadata.” The line was not a boast about breaking encryption. It was the opposite point: for a great many purposes, nobody needs to. The earlier posts in this series looked at what encryption guarantees, and at who holds the keys. This one concerns everything those guarantees leave exposed: the data about the data. Who communicated with whom. When, how often, in what bursts, from which locations, on which devices, in messages of what size. Content encryption – even flawless, end-to-end, key-custody-correct encryption – conceals none of it.

Read article

Zero-Knowledge Proofs: Proving Without Revealing, Separating Substance From Theatre

A zero-knowledge proof lets one party prove to another that a statement is true whilst revealing nothing beyond the truth of the statement itself: not the evidence, not the underlying data, not the working, only the fact. It sounds like a conjuring trick, and most people, hearing it described, assume it cannot be done. It can. The technique is not new. It was set out in a 1985 paper by Goldwasser, Micali and Rackoff; two of the three, Goldwasser and Micali, went on to receive the Turing Award, in 2012, for a body of work in cryptography of which this was a part. What has changed recently is practicality. Proofs that once demanded impractical amounts of computation can now be generated quickly enough for production systems, and the phrase has duly made its way from the journals onto the product brochures. That journey has not been kind to precision. What follows sets out what the technique actually offers, where it is earning its keep, and how to spot the cases where the phrase is carrying more weight than the mathematics.

Read article

What End-to-End Encryption Actually Guarantees — and What It Quietly Doesn't

Few phrases in technology have travelled as far from their technical meaning as “end-to-end encrypted”. It now appears on platforms whose architectures differ so fundamentally that the shared label conveys almost nothing. For an organisation deciding where its sensitive communication should live, the label is the start of the inquiry, not the end of it. This post sets out, as precisely as a general audience allows, what end-to-end encryption guarantees, the conditions attached to that guarantee, and the substantial ground it does not cover.

Read article