Draft National Encryption Policy looking to ban encryption tech not registered with government

Users within C group (i.e. C2C Sector) may use Encryption for storage and communication. Encryption algorithms and key sizes will be prescribed by the Government through Notification from time to time. All citizens (C), including personnel of Government / Business (G/B) performing non-official / personal functions, are required to store the plaintexts of the corresponding encrypted information for 90 days from the date of transaction and provide the verifiable Plain Text to Law and Enforcement Agencies as and when required as per the provision of the laws of the country.
 
They forgot to mention that the keys will be stored and available in the clouds in the sky.
 
they require you to keep the unencrypted content with you for 90 days and provide it if required for legal reasons. i am surprised about the 90 day requirement. so basically encryption itself is removed from the equation if the content is less than 3 months old. not sure what policy they plan to apply on older content. i am guessing they would push for keys if the content is older. some of the approved encryption technologies are in fact already broken and unsafe for use.


Source
 
why not just make a law that - one must provide private keys when demanded by legal authorities.

or better... why dont we just go back to paper-age.
 
Well. Indian govt should come up with a simple ass policy.

Only Paper based encryption will be allowed.
How this works?
Well, whatever data you want to encrypt, you print it on a paper and fold it and put it in an envelope and seal it. That document is encrypted now. Tearing the envelope would amount to decrypting the data. To recrypt, get a new envelope as using the old envelope(key) would make your document insecure.
 
Back