{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,29]],"date-time":"2026-05-29T08:44:14Z","timestamp":1780044254000,"version":"3.53.1"},"reference-count":41,"publisher":"Oxford University Press (OUP)","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["J Cyber Secur"],"DOI":"10.1093\/cybsec\/tyv009","type":"journal-article","created":{"date-parts":[[2015,11,17]],"date-time":"2015-11-17T21:49:18Z","timestamp":1447796958000},"page":"tyv009","source":"Crossref","is-referenced-by-count":48,"title":["Keys under doormats: mandating insecurity by requiring government access to all data and communications"],"prefix":"10.1093","author":[{"given":"Harold","family":"Abelson","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ross","family":"Anderson","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Steven M.","family":"Bellovin","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Josh","family":"Benaloh","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Matt","family":"Blaze","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Whitfield","family":"Diffie","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"John","family":"Gilmore","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Matthew","family":"Green","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Susan","family":"Landau","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Peter G.","family":"Neumann","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ronald L.","family":"Rivest","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jeffrey I.","family":"Schiller","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bruce","family":"Schneier","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michael A.","family":"Specter","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Daniel J.","family":"Weitzner","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"286","published-online":{"date-parts":[[2015,11,17]]},"reference":[{"key":"2016010804073474000_tyv009v1.1","unstructured":"Abelson H Anderson RN Bellovin SM. . The Risks of Key Recovery, Key Escrow, and Trusted Third-Party Encryption, 1997. http:\/\/academiccommons.columbia.edu\/catalog\/ac:127127 (26 October 2015, date last accessed)."},{"key":"2016010804073474000_tyv009v1.2","unstructured":"Advanced Telephony Unit, Federal Bureau of Investigation. Telecommunications Overview, Slide on Encryption Equipment, 1992. https:\/\/www.cs.columbia.edu\/\u223csmb\/Telecommunications_Overview_1992.pdf (26 October 2015, date last accessed)."},{"key":"2016010804073474000_tyv009v1.3","unstructured":"Nakashima E. Chinese hackers who breached Google gained access to sensitive data, U.S. officials say. The Washington Post, May 2013. https:\/\/www.washingtonpost.com\/world\/national-security\/chinese-hackers-who-breached-google-gained-access-to-sensitive-data-us-officials-say\/2013\/05\/20\/51330428-be34-11e2-89c9-3be8095fe767\\_story.html (26 October 2015, date last accessed)."},{"key":"2016010804073474000_tyv009v1.4","unstructured":"Dam KW Lin HS. . Cryptography\u2019s Role in Securing the Information Society. National Academies Press, 1996."},{"key":"2016010804073474000_tyv009v1.5","unstructured":"Comey JB . Going Dark: Are Technology, Privacy, and Public Safety on a Collision Course? Speech at the Brookings Institution, October 2014. https:\/\/www.fbi.gov\/news\/speeches\/going-dark-are-technology-privacy-and-public-safety-on-a-collision-course (26 October 2015, date last accessed)."},{"key":"2016010804073474000_tyv009v1.6","unstructured":"Cameron D . PM: Spy Agencies Need More Powers to Protect Britain, January 2015. https:\/\/embed.theguardian.com\/embed\/video\/uk-news\/video\/2015\/jan\/12\/david-cameron-spy-agencies-britain-video (26 October 2015, date last accessed)."},{"key":"2016010804073474000_tyv009v1.7","doi-asserted-by":"crossref","unstructured":"Blaze M . Protocol failure in the escrowed encryption standard. In: Proceedings of the 2nd ACM Conference on Computer and Communications Security, Fairfax, VA: ACM, 1994, p. 59\u201367.","DOI":"10.1145\/191177.191193"},{"key":"2016010804073474000_tyv009v1.8","doi-asserted-by":"crossref","unstructured":"Diffie W Landau S . The Export of Cryptography in the 20th Century and the 21st. In Karl De Leeuw Jan Bergstra (eds.), The History of Information Security: A Comprehensive Handbook, Amsterdam: Elsevier, 2007, pp. 725\u2013736.","DOI":"10.1016\/B978-044451608-4\/50027-4"},{"key":"2016010804073474000_tyv009v1.9","unstructured":"Ford P , The Obamacare Website Didn\u2019t Have to Fail. How to Do Better Next Time, October 2013. http:\/\/www.bloomberg.com\/bw\/articles\/2013-10-16\/open-source-everything-the-moral-of-the-healthcare-dot-gov-debacle (26 October 2015, date last accessed)."},{"key":"2016010804073474000_tyv009v1.10","unstructured":"Eggen D Witte G . The FBI\u2019s upgrade that wasn\u2019t. The Washington Post, August 2006. http:\/\/www.washingtonpost.com\/wp-dyn\/content\/article\/2006\/08\/17\/AR2006081701485.html (26 October 2015, date last accessed)."},{"key":"2016010804073474000_tyv009v1.11","unstructured":"Vijayan J. TJX Data Breach: At 45.6m Card Numbers, It\u2019s the Biggest Ever, March 2007. http:\/\/www.computerworld.com\/article\/2544306\/security0\/tjx-data-breach--at-45-6m-card-numbers--it-s-the-biggest-ever.html (26 October 2015, date last accessed)."},{"key":"2016010804073474000_tyv009v1.12","unstructured":"Krebs B , Security Fix - Payment Processor Breach May Be Largest Ever, January 2009. http:\/\/voices.washingtonpost.com\/securityfix\/2009\/01\/payment\\_processor\\_breach\\_may\\_b.html (26 October 2015, date last accessed)."},{"key":"2016010804073474000_tyv009v1.13","unstructured":"Abelson R Goldstein M. Anthem hacking points to security vulnerability of health care industry. The New York Times, February 2015. http:\/\/www.nytimes.com\/2015\/02\/06\/business\/experts-suspect-lax-security-left-anthem-vulnerable-to-hackers.html (26 October 2015, date last accessed)."},{"key":"2016010804073474000_tyv009v1.14","unstructured":"Thornburgh N. The invasion of the Chinese cyberspies. Time, August 2005. http:\/\/content.time.com\/time\/magazine\/article\/0,9171,1098961,00.html (26 October 2015, date last accessed)."},{"key":"2016010804073474000_tyv009v1.15","unstructured":"Lynn William J III , Defending a new domain. Foreign Affairs, October 2010. https:\/\/www.foreignaffairs.com\/articles\/united-states\/2010-09-01\/defending-new-domain (26 October 2015, date last accessed)."},{"key":"2016010804073474000_tyv009v1.16","unstructured":"Coviello A . Open Letter from Arthur Coviello, Executive Chairman, RSA, Security Division of EMC, to RSA Customers, March 2011."},{"key":"2016010804073474000_tyv009v1.17","unstructured":"Meserve J. Sources: Staged Cyber Attack Reveals Vulnerability in Power Grid - CNN.com, CNN, September 2007. http:\/\/www.cnn.com\/2007\/US\/09\/26\/power.at.risk\/index.html?iref=topnews (26 October 2015, date last accessed)."},{"key":"2016010804073474000_tyv009v1.18","unstructured":"Zetter K. A Cyberattack Has Caused Confirmed Physical Damage for the Second Time Ever, January 2015. http:\/\/www.wired.com\/2015\/01\/german-steel-mill-hack-destruction\/ (26 October 2015, date last accessed)."},{"key":"2016010804073474000_tyv009v1.19","unstructured":"George R. Views on the Future Direction of Information Assurance, July 2002, remarks by Richard George at Blackhat Las Vegas. https:\/\/www.blackhat.com\/presentations\/bh-usa-02\/bh-us-02-george-keynote.doc (26 October 2015, date last accessed)."},{"key":"2016010804073474000_tyv009v1.20","first-page":"26","volume-title":"The Athens Affair, Spectrum, IEEE","volume":"Vol. 44","author":"Prevelakis","year":"2007"},{"key":"2016010804073474000_tyv009v1.21","unstructured":"Cross T . Exploring Lawful Intercept to Wiretap the Internet, Washington, DC, USA, 2010. https:\/\/www.blackhat.com\/presentations\/bh-dc-10\/Cross\\_\u00a0Tom\/BlackHat-DC-2010-Cross-Attacking-LawfulI-Intercept-slides.pdf (26 October 2015, date last accessed)."},{"key":"2016010804073474000_tyv009v1.22","unstructured":"George R. Private communication between Richard George, Former Technical Director, Information Assurance Directorate, NSA and Susan Landau, December 2011."},{"key":"2016010804073474000_tyv009v1.23","unstructured":"Perlroth N Goel V . Twitter Toughening Its Security to Thwart Government Snoops, November 2013. http:\/\/bits.blogs.nytimes.com\/2013\/11\/22\/twitter-toughening-its-security-to-thwart-government-snoops\/ (26 October 2015, date last accessed)."},{"key":"2016010804073474000_tyv009v1.24","unstructured":"Seltzer. Google Moves Forward Towards a More Perfect SSL, November 2013. http:\/\/www.zdnet.com\/article\/google-moves-forward-towards-a-more-perfect-ssl\/ (26 October 2015, date last accessed)."},{"key":"2016010804073474000_tyv009v1.25","unstructured":"Gupta D . Google Enables \u201cForward Secrecy (PFS)\u201d by \u201cDefault\u201d for HTTPS Services, November 2011. http:\/\/www.ditii.com\/2011\/11\/23\/google-enables-forward-secrecy-pfs-by-default-for-https-services\/ (26 October 2015, date last accessed)."},{"key":"2016010804073474000_tyv009v1.26","unstructured":"Larson S . After Heartbleed, \u201cForward Secrecy\u201d Is More Important Than Ever, April 2014. http:\/\/readwrite.com\/2014\/04\/15\/heartbleed-perfect-forward-secrecy-security-encryption (26 October 2015, date last accessed)."},{"key":"2016010804073474000_tyv009v1.27","unstructured":"Langley A . Protecting Data for the Long Term with Forward Secrecy, November 2011. http:\/\/googleonlinesecurity.blogspot.com\/2011\/11\/protecting-data-for-long-term-with.html (26 October 2015, date last accessed)."},{"key":"2016010804073474000_tyv009v1.28","unstructured":"Kiss J . Twitter Adds More Security to Thwart Predators and Government Agencies, November 2013. http:\/\/www.theguardian.com\/technology\/2013\/nov\/23\/twitter-security-google-facebook-data-nsa (26 October 2015, date last accessed)."},{"key":"2016010804073474000_tyv009v1.29","unstructured":"Higgins P . Pushing for Perfect Forward Secrecy, an Important Web Privacy Protection, August 2013. https:\/\/www.eff.org\/deeplinks\/2013\/08\/pushing-perfect-forward-secrecy-important-web-privacy-protection (26 October 2015, date last accessed)."},{"key":"2016010804073474000_tyv009v1.30","unstructured":"Mimoso M . Microsoft Expands TLS, Forward Secrecy Support | Threatpost | The First Stop for Security News, July 2014. https:\/\/threatpost.com\/microsoft-expands-tls-forward-secrecy-support\/106965 (26 October 2015, date last accessed)."},{"key":"2016010804073474000_tyv009v1.31","unstructured":"Mimoso M . Microsoft Brings Perfect Forward Secrecy to Windows | Threatpost | The First Stop for Security News, May 2015. https:\/\/threatpost.com\/new-crypto-suites-bring-perfect-forward-secrecy-to-windows\/112783 (26 October 2015, date last accessed)."},{"key":"2016010804073474000_tyv009v1.32","unstructured":"Bright P . Microsoft Expands the Use of Encryption on Outlook, OneDrive, July 2014. http:\/\/arstechnica.com\/security\/2014\/07\/microsoft-expands-the-use-of-encryption-on-outlook-onedrive\/ (26 October 2015, date last accessed)."},{"key":"2016010804073474000_tyv009v1.33","unstructured":"Tung L . Yahoo Finally Enables HTTPS Encryption for Email by Default, January 2014. http:\/\/www.zdnet.com\/article\/yahoo-finally-enables-https-encryption-for-email-by-default\/ (26 October 2015, date last accessed)."},{"key":"2016010804073474000_tyv009v1.34","unstructured":"Apple, iOS Security on iOS 8.3 or Later, Tech. Rep., April 2015. https:\/\/www.apple.com\/business\/docs\/iOS\\_Security\\_Guide.pdf (26 October 2015, date last accessed)."},{"key":"2016010804073474000_tyv009v1.35","unstructured":"Perlroth N. Electronic security a worry in an age of digital espionage. The New York Times, February 2012. http:\/\/www.nytimes.com\/2012\/02\/11\/technology\/electronic-security-a-worry-in-an-age-of-digital-espionage.html (26 October 2015, date last accessed)."},{"key":"2016010804073474000_tyv009v1.36","unstructured":"Thompson B. UAE Blackberry update was spyware. BBC, July 2009. http:\/\/news.bbc.co.uk\/2\/hi\/8161190.stm (26 October 2015, date last accessed)."},{"key":"2016010804073474000_tyv009v1.37","unstructured":"Chang FR. Is Your Data on the Healthcare.gov Website Secure? Written Testimony, U.S. House of Representatives, November 2013. http:\/\/docs.house.gov\/meetings\/SY\/SY00\/20131119\/101533\/HHRG-113-SY00-Wstate-ChangF-20131119.pdf (26 October 2015, date last accessed)."},{"key":"2016010804073474000_tyv009v1.38","doi-asserted-by":"crossref","unstructured":"Beurdouche B Bhargavan K Delignat-Lavaud A. . A messy state of the union: taming the composite state machines of TLS. In: IEEE Symposium on Security and Privacy, 2015. https:\/\/www.smacktls.com\/smack.pdf (26 October 2015, date last accessed).","DOI":"10.1109\/SP.2015.39"},{"key":"2016010804073474000_tyv009v1.39","unstructured":"Colaprico P . \u201cDa Telecom dossier sui Ds\u201d Mancini parla dei politici - cronaca - Repubblica.it , January 2007. http:\/\/www.repubblica.it\/2006\/12\/sezioni\/cronaca\/sismi-mancini-8\/dossier-ds\/dossier-ds.html (26 October 2015, date last accessed)."},{"key":"2016010804073474000_tyv009v1.40","first-page":"993","volume-title":"Using Encryption for Authentication in Large Networks of Computers, Communications of the ACM","volume":"Vol. 21","author":"Needham","year":"1978"},{"key":"2016010804073474000_tyv009v1.41","doi-asserted-by":"crossref","unstructured":"Lowe G. An Attack on the Needham-Schroeder Public-key Authentication Protocol, Information Processing Letters, Vol. 56, pp. 131\u20133, November 1995. http:\/\/dx.doi.org\/10.1016\/0020-0190(95)00144-2 (26 October 2015, date last accessed).","DOI":"10.1016\/0020-0190(95)00144-2"}],"container-title":["Journal of Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/academic.oup.com\/cybersecurity\/article-pdf\/1\/1\/69\/7002861\/tyv009.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,9,1]],"date-time":"2019-09-01T12:54:18Z","timestamp":1567342458000},"score":1,"resource":{"primary":{"URL":"https:\/\/academic.oup.com\/cybersecurity\/article-lookup\/doi\/10.1093\/cybsec\/tyv009"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015,11,17]]},"references-count":41,"alternative-id":["10.1093\/cybsec\/tyv009"],"URL":"https:\/\/doi.org\/10.1093\/cybsec\/tyv009","relation":{},"ISSN":["2057-2085","2057-2093"],"issn-type":[{"value":"2057-2085","type":"print"},{"value":"2057-2093","type":"electronic"}],"subject":[],"published":{"date-parts":[[2015,11,17]]}}}