Forcing suspects to reveal phone passwords is unconstitutional, court says
arstechnica.com
arstechnica.com
so, my normal code might be 123456, but if someone asks what my code is and I say 345678, then the phone does a data wipe that isn't obvious from the outside, and just deletes all credentials, cookies, history, documents, etc.
Is this workable?
A judge isn't a robot. If you say "I hit an emergency button to reformat my hard drives as the cops were breaking down the door, because I was preparing to sell those drives on ebay and needed to clean them up", the judge is not obligated to respond "Shoot, I can't prove otherwise, you're free to go."
The only marketable purpose for an instant erasure system like that is protection of information (personal or commercial). To build that, you'd make something that zeros all the files and deletes them, deletes and overwrites all the contacts, and such.
But the structures left after that don't look like a brand new device. They look like you had a bunch of things and then erased them. Cops won't know what you erased, but they'll know you handed them a phone that was recently erased.
Now maybe somebody will build an app tuned for obstruction of justice, so it tries to make the phone look brand new. And maybe you'll be very lucky and they'll get it working perfectly on your specific phone. But then you have to explain how you have a brand new phone that was actually purchased a year ago. And how it has no record of any of the calls that your phone carrier will have records of. The obvious conclusion is that you wiped it sometime after your last call and with special software that only appeals to people planning on hindering an investigation.
Is that enough to convict you for obstruction of justice? I have no idea; it probably depends on how much a prosecutor cares. But is it enough to convince cops you are vigorously hiding something? You bet.
No, there's no need for anything that complicated.
In principle, encrypting all data on a phone is really simple to implement. In practice, it's carefully thought out to avoid edge cases. The general idea is something like this:
when first activated, the
phone generates a random 256-bit AES key
phone uses this random AES key to encrypt
all data stored on the phone
phone retains this random key in a special
location, and encrypts this key by using
the user-provided PIN
To quickly erase all data on the phone, all that's necessary is to overwrite the key in the special location with random data. From that point on, there is no feasible way to recover anything on the phone. Period.It isn't necessary to erase an entire device. It's merely necessary to replace a 32-byte field (that contains the true AES key) with 32-bytes of random data.
From then on, it doesn't matter what the PIN is. Data on the phone is jibberish unless and until the proper 256-bit AES key is produced. That key no long exists, so from that point on the only way to recover the data is by brute forcing AES, by trying all possible 2^256 combinations.
They look like you had a bunch of things and then erased them
No, what remains is indistinguishable from the case where the correct PIN hasn't been provided. Having "things" on the phone is no evidence of guilt. There is absolutely no evidence that the phone was erased. All that is known is that the provided PIN isn't able to decrypt the data.
What we were discussing is abakker's proposal for something that "wipes the phone", and I think my comments are still relevant to that approach.
Of course, a suddenly unreadable phone is still suspicious, but if your plan were perfectly implemented, it might be impossible to prove obstruction of justice.
This seems like one of those laws that sounds good at first but makes a lot of normal behavior illegal, thus allowing the legal system to be able to pick and choose who gets punished.
Similarly, did you know you can legally murder anyone by poisoning their food? You didn't make them eat the poison, they voluntarily ate the food. It gets ruled a suicide.
For more on this and other little-known facts about the law, please subscribe to my YouTube Guide to Being a Sovereign Citizen, only $199/month.
Investigators are going to take a very dim view of such events, and probably didn't get to the point of demanding access without having documented sensible reason to believe the evidence is there - and may very well have actionable proof that you destroyed evidence, which will not turn out in your favor.
So patent examiners cannot just look at something and say, "this is crap, no patent for you". They have to prove a patent application invalid. There are many ways to do this, but the most common is by showing sufficient prior art. If they cannot find one or more previously published works that disclose each and every element of the claim, they must allow it. Apparently the examiner could not find evidence of somebody thinking of this before, and so it was allowed, regardless of how novel it appears to us now.
Another way to find an application invalid is to show that it does not disclose enough detail about how to implement the invention. That is probably why this patent (and most others) are really long-winded.
I think of touch UIs and the patents there, for example Apple's rubber-band scrolling patent[2]. Sure, it's quite probable that no one thought of this before if they weren't designing touch UIs. And even if they were, they might have thought of that, plus several other ideas, while developing. Why should this make any difference?
For instance, no one has made scrolling that intentionally segfaults if you scroll fast enough (or insert other silly thing here). You won't find prior art on this. Should it be eligible for a patent just because it's novel? There should be some sort of criteria where the effort required to invent something is taken into account. If it's likely to come about merely as a result of playing in the space, then what does the public gain by issuing a patent?
What knowledge is contained in the "reverse PIN dials cops" that merits protection? Even if nobody had that idea before (or bothered to document it), what does that matter? If you patent can be constructed just by asking a simple question ("think of some ways to alarm when being robbed at an ATM"), well that should be grounds for it not being valid.
Edit: Another example. Things like algorithms. Look at a simple database indexing system: ISAM. Sort your data, sample every so often to form an index. Repeat if the index is too large. Ta-da. Going back far enough, this was very novel. But any worker that had to figure this problem out would arrive at the same solution. It's nearly as fundamental as binary search.
1: https://en.wikipedia.org/wiki/Inventive_step_and_non-obvious...
2: http://patft.uspto.gov/netacgi/nph-Parser?Sect1=PTO1&Sect2=H...
One line of reasoning is that there are not enough people "merely playing in some space" to find more solutions to problems. This is not just theoretical. There is empirical evidence based on historical data that showed how the introduction of patent protection to previously ineligible arts influenced innovation. It finds there was more innovation in areas where previously protection was not available or where it was too easy for competitors to rip off your inventions. See http://www.jstor.org/stable/4132712 for instance.
> If you patent can be constructed just by asking a simple question...
Many scientists, mathematicians and engineers will tell you that the best way to solve a difficult problem is by framing it correctly. Put another way, you have to first ask the right questions. The solution may become obvious then, but it may be very hard to first ask the right question. And hindsight is a very powerful bias. What may seem like a simple question today may not actually have been so before it was posed.
This is also one of the many problems with requiring effort as a criteria. Besides being difficult to quantify in general, how do you measure the effort required to formulate the right question? How do you quantify flashes of insight? Maybe a person has 20 years of experience in some field X, but sees a problem and reaches a solution in 20 seconds. Was the effort required 20 seconds or 20 years?
The same place also had a security system for a critical data center room: Opening the door from the outside (i.e. entering) would increment a counter by one, opening it from the inside would decrement it. If the room, according to that counter, was supposed to be empty, any movement within would trigger the same silent alarm. The system worked safely up to the point where two people entered together, one of them left the room and the other one's badge had a temporary malfunction. We were quite impressed with how quickly a large assortment of police would show up, guns blazing and all ;-)
Your doubt tells us that your PIN is not a palindrome. The second most common PIN is 1-1-1-1, followed by 0-0-0-0 (says http://www.datagenetics.com/blog/september32012/ ), and looking at the top 20 numbers, over 10% of the people have a palindromic PIN. (If selected randomly, that should be 2%.)
So either the police get called a lot, or there's some special flag that say "palindrome PIN - false alarm" (and it must be supported for international cards) ... or it's simply not true.
Wells Fargo and a couple others allow anywhere from 8-16 as their maximum, though I reduced mine to 12 because some ATM's were kind of finicky at the longer lengths.
Luckily (hah) working for a US company so I don't get enough time off to actually go overseas, so it's never been something I had to worry about.
Edit: It doesn't seem so weird anymore either. I used to get questions all the time from Cashiers, like "Wow, I didn't know your PIN could be longer than 4". But I haven't been asked about it in 1-2 years.
More important to the issue at hand, I believe that in at least one case the reason for the passcode/phrase being "testimony" isn't so much that you're revealing what's in the locked container, but that you're demonstrating that you have access to/control over its contents. So entering your erasecode would undermine this point. A courier could not know a passphrase yet be deputized to erase the contents, but that is going to be an uphill argument.
What we really want is a proper layered steganographic filesystem, with an arbitrary number of unlockable levels. But we need an OS and apps that play nicely with that as well.
The first layer contains something embarrassing but legal like gay porn, and the second layer contains the stuff you really want to hide.
You just unlock the first layer and act really embarrassed if forced and never acknowledge the existence of the second layer.
http://security.stackexchange.com/questions/9058/is-it-possi...
What do the proponents of these encryption laws expect the penalties to be for 'suspicion of possession of encrypted material'? I don't see any way to create effective deterrents here without making it easy to persecute anyone for any reason. Imagine cops planting USB keys with random bits on minorities they don't like, etc.
Edit: or worse, 15-year-olds planting USB keys with random bits on teachers they don't like and claiming it's CP and then watching them get fired and go to prison for 'refusal to decrypt' shudder
Just because something isn't proof, doesn't mean it isn't evidence. And if I am doing something my government disproves of, I'm going to try and be mindful of all evidence that can expose that. (Note that I'm NOT making any value judgements here) If an inner-hidden volume isn't as hidden as I thought it was, then that's a security risk to me.
a) 'forced decryption' legislation is toothless. That is, suspicion, but not proof that encrypted material exists and is within your power to decrypt is not enough to throw you in jail for contempt or some other charge.
b) It becomes extremely easy for bad actors like racist cops or asshole teenagers to frame anyone and everyone they want and put them in prison forever.
I could even see it with touch sensors, that being teaching it that the middle finger wipes the puppy.
With regards to the court decision, I am not sure it will stand in this context. The phones belong to the employer and not the employees. So how as an employer do you retain some access over your provided phones? I can see both sides here. To be honest as a company I don't think its worth the legal ramifications to have power over the content of the phone as it just opens a can of worms
Where I work we are required to pass code our phones if we access the corporate internet or exchange servers but we are not required to divulge our phone contents, passcode, nor place software on the phone giving the company any such ability.
There's no law against incompetence, true?
There was a case a few years back (discussed on HN) where a gang had software installed on everyone's phone that caused a remote wipe when activated. The cops did a big raid, and even though they took everyone's phone someone they hadn't caught yet was able to wipe them.
The cops changed their SOP so that when they get ahold of your phone the first thing they do is yank the battery.
Depends on the situation. If it's a raid due to software piracy - then probably. If they pulled you over for speeding and arresting you - they probably won't or even know what to look for.
And I really can't think of a way to clone a device like an Android device without unlocking it. ADB now a days requires your explicit permission from a prompt. And if you are like "oh they have ways" I would be very interested in that because that sounds like whatever they are doing are using an exploit or some sort of back door.
No, they don't need to use any kind of exploit. They have hardware that allows them to clone the the device's memory. I doubt it has to be on at all.
There's no way to secure a device if the attacker has physical access. The best you can do is secure the data with encryption.
The link is a few years old. No idea if there is a current version that works on modern phones, but it seems reasonable to assume there would be.
The first part talks about bluetooth pairing with the device - which requires unlocking. The second page talks about unlocking an iPhone with plist files from a synced computer. So it's not a matter of some magical device that can backdoor a phone - but rather using interfaces that already exist.
I found this company [2] and it has the usual marketing ploy - but a quick google search doesn't reveal any actual reviews of people using it. I can paragraphs of marketing spin but no one actually saying "we used this to get into cell phones that were password protected".
I'm not saying it's not possible - I just find it hard to believe without it making modifications to the underlying software (ie flashing a ZIP on android that zeros out the pin password or something).
[1] http://arstechnica.com/tech-policy/2011/04/michigan-state-po...
[2] http://www.cellebrite.com/Mobile-Forensics/Products/ufed-tou...
It would only take seconds to use, but you would need to be prepared for the specific phone model.
Maybe you could even have a CNC machine preloaded with the data for a wide variety of phone models. You put the phone down on the work surface, key in the model, and the CNC machine deftly cuts through the right power lead. Less portable, but would require less precise planning.
But what I wonder is how they circumvent the entire trust mechanic when the phone is locked. When the phone is locked most of the storage is encrypted too.
I've always thought the way to deal with this is to use a OTP scheme. If you have a one time pad that's as large as your data set (assuming we're talking about some reasonably small number of critical documents here), you could generate the cyphertext from your key and then generate another key that translates your cyphertext into something innocuous - grocery lists or whatever.
There's no way the court could prove the key you gave them isn't the right key.
If they can copy the HSM, that wouldn't help, but in that case, it doesn't really seem like they need your help getting the PIN in the first place.
That's something I hadn't considered. Is it set up that you can create and destroy the keys but never get access to them?
I know in the Windows Mobile/Blackberry days if you typed in the incorrect password so many times it would reset the device.
However, with many Android devices now a days have the ability to have a "guest mode" - that is activated using a different unlock code. This mode can be limited to not even be able to make/receive calls. Arguably most people won't know what this "mode" is and if they are in it.
Perhaps some software that clears the phone when someone tries to break into the phone / copy data? A prudent security precaution for all sorts of reasons.
Edit: I missed the part where he's a former federal prosecutor. Mystery solved.
The fact that you have a phone, which could contain something, doesn't make the phone case any different.
If my password is "iKilledColonelMustardWithACandlestick" - and it's actually an incriminating fact, how does that factor into potentially self-incriminatory discovery?
So make sure that your password is an admission of whatever crime for which your phone contains evidence.
Does it work that way? Can you legally compel self-incriminating speech as long as you offer immunity?
If that was true, why wouldn't it be used all the time to incriminate other people? Currently they need to get the subject to agree to such a deal, or so the impression I get from the media is.
https://www.washingtonpost.com/news/volokh-conspiracy/wp/201...
I know there are folks here on HN who believe that they should have an absolute power to exclude the government at all times. I'm not one of them, though. Particularly in situations where law enforcement has obtained a lawful warrant, I think they should have a way to get that information. People do commit crimes, and the police do need to solve them.
One way to grant the police access is to somehow give them privileged access to the encryption. For me, this idea is dead on arrival. There is no way to grant privileged access to the police without dangerously weakening the encryption in general. I'm a believer that encryption, properly implemented without backdoors, creates a lot more good than bad.
So what does that leave? It leaves compelling the owner of the phone to unlock it. If the police get a warrant to search your house, you are legally required to unlock the door and let them in. It seems to me that a passcode on the phone serves exactly the same purpose.
So, my concern is that if compelling the phone owner to unlock is not an option, it will put a lot more pressure behind the idea of encryption backdoors, as the "only option" to give law enforcement the power they need to do their jobs.
My point is that when a bad idea appears to be the only alternative, there will be pressure (from people who do not understand the technology but do understand law enforcement) to do it even though it's bad.
Given the choice, I'd rather have warrants compelling people to unlock, than a law saying that encryption has to have a backdoor so law enforcement can force their way in.
If I were to go through my old hard drives, USBsticks and whatnot, I'm reasonably sure I'd stumble on to random blocks of data and/or encrypted archives with passwords long since forgotten. If I could be punished for not producing matching passphrases, those could become a huge liability, very quickly.
Keep in mind, almost all this data lives elsewhere too. If it's important enough they can still get it.
In the end it boils down to the simply dilemma of choosing between either catching all "criminals" or protecting the rights of the people.
The latter way of course makes life a bit harder, since you'll never be able to prevent all crimes and people will potentially die, but people die all the time, since dying is a a basic risk of life.
The former way is essentially a rabbit hole, because it allows you to rewrite the definition of a "criminal" to just about anything you'd like and once you get a court order the "criminal" being is pretty much done with their life. This of course was and is still used in dictatorships of all kinds of sizes and employed by numerous secret police agencies around the world. Once there is a way to criminalize any action and then instantly "get rid" of that person, people who are going to use these powers WILL pop up and take over power.
Now of course in the short term no third party candidate is going to show up on the US politcal floor and take win a majority in the elections over night and then install a dictator system based on all the pre-existing powers by simply outlawing all other parties and anyone who objects to the new rulers claims. But 10 or 20 years from now things might be different and if we don't fight over abuse of the law and protect the general public we might end up in a pretty bad situation someday.
The oversight on the judge? Higher-level judges. If you are arrested after a warrant that is later found to be invalid, the evidence collected based on the warrant is thrown out. This can go all the way to the supreme court. As it did in Franks v Delaware: https://en.wikipedia.org/wiki/Franks_v._Delaware
It's not totally unreasonable. On the other hand, there's the 5th amendment, and you are not actually required to open the door when presented with a warrant, that's just a way of saving your door.
Let's take it one step back from electronic devices.
If a corrupt businessman kept encoded records in a notepad, the authorities could compel him to turn over that notebook but no warrant can compel him to explain its contents. That's what encryption is. They authorities can seize the device but they can not force you to explain how to interpret what's in it.
Fortunately, high profile data breaches have put the thought in the public mind that weaknesses can be exploited. We can use that concern to keep people from demanding back-doors.
For example, under the law I have the right to go to the Moon. But I don't have the ability. Having the right doesn't compel anyone to create that ability for me.
Back to the issue at hand, I believe the government should have the right to access any information relevant to a criminal investigation, if they have a warrant for it. But I don't think they should be able to compel the ability. At best they should be able to compel that people don't interfere, but the actual ability to access the material is up to them. So while I don't think I fall into that category of person you describe as "believe that they should have an absolute power to exclude the government," I also think that given the current state of technology, that power does exist.
I'm not really worried about backdoors. They look to me to be so ridiculous that it won't even be possible to attempt to mandate them. Even if they are mandated, how will that be enforced? The genie is far out of the bottle on this.
The law gives police the right to enter your premises if they have a valid search warrant. But it also gives them the rams, guns, body armor, etc.--the ability to exercise that right.
From a practical perspective, lawmakers try to address both rights and abilities when crafting legislation that enforces laws. I think it's really unlikely that politicians would say "here's the right, but the ability is your problem." No, they'll write a law that gets the effect they want, even if means granting powers that seem ridiculous to us. There is no shortage of things that have the force of law today despite seeming ridiculous to us.
I am worried about backdoors. They are being seriously considered at the highest levels of government.
That's the problem with encryption, it's totally unlike anything else that exists in the world. It's impossible (so far) to prove whether someone legitimately forgot the password, or if they're just saying that they forgot it in order to hide/destroy evidence.
What other thing quite literally may or may not exist, depending on the state of a person's mind?
Also in terms of a phone, it's easy to tell if it is encrypted, because modern phone operating systems encrypt by default. So the question is whether a person can be compelled to give their password.
If the person wants to assert that they cannot provide the password because they forgot it, that is a defense that can be evaluated in a trial. Is the person lying, or did they really forget it? The court system exists to resolve questions like that. EDIT TO ADD: I'm just making the point that the possibility that someone might claim they forgot their password does not in any way prevent the passage of a law requiring people to provide their password. People try various tricks to get around all sorts of laws--that's why we have a court system.
It'd be like trying to determine with 100% accuracy what a person's favorite color is. No matter how many witnesses you call and how many decades of documentation that it's blue you have, that doesn't make it blue. It just meant it was blue.
Oscar Pistorius shot and killed his girlfriend. "I thought she was an intruder; I did not mean to hurt her," he said (paraphrase). The facts were not in doubt; the entire case hinged on whether the jury believed he was telling the truth.
I agree that there is no way to recover a passcode from the brain (outside of science fiction). But it seems like a court could rule on whether claims of forgetfulness are real.
Further, any random assortment of bits is potentially an encrypted volume. At least with a murder there is a body. With a "forgotten" password -- or a password you never had to begin with because there is no encrypted volume -- nothing bad has to happen. So it's far more likely to be abused to put people behind bars that "we know did it" but where the police or whoever can't get them on anything else. Like how mobsters often go to jail for tax evasion rather than the violent stuff.
In terms of the encrypted volume, law enforcement has to prove each step on its own. They can't seize the computing device until they prove it is actually likely to contain evidence relevant to the prosecution of a crime. And they can't ask a suspect for their passcode until they prove that there is actually an encrypted volume to be unlocked (this is probably easier than you think). And if the person says they forgot the password, law enforcement would have to prove that they are lying.
Courts already handle similar situations with contempt and perjury proceedings. Even though criminal contempt or perjury is usually secondary to the "main case," it has to be proven beyond a reasonable doubt just like any other crime.
That's why it's not "abuse." It's not like law enforcement can magically lower the bar for conviction by some special procedure. When Al Capone went to jail for tax evasion, he really had evaded taxes, and the government proved it beyond a reasonable doubt.
The idea that the police or prosecutor has to "prove" all this stuff is nice, but not in line with reality. Warrants get issued on suspicion all the time. There's not a pre-trial trial to determine in front of a jury if the suspected encrypted volume is in fact an encrypted volume.
The judge orders you to provide the password and if you don't you're held in contempt for as long as you don't. Which, if you don't know the password, could be the rest of your life.
That's why some in law enforcement might be tempted to invent an encrypted volume that doesn't exist. Because it short-circuits the normal judicial process. And when you know someone is guilty but the damn red tape gets in the way, it can be tempting to try and make things "right".
Mental states -- including knowledge of specific facts, intent, belief, etc. -- are necessary elements of many offenses are determined by courts in the same way as any other facts.
> It'd be like trying to determine with 100% accuracy what a person's favorite color is.
No, its not, because even the "beyond a reasonable doubt" standard for criminal prosecutions is not targeting 100% accuracy, which would be unattainable for any class of facts (not just mental states.)
You're constructing a false dichotomy. Backdooring all encryption and compelling the accused to provide a password are not the only alternatives. And they're both terrible.
You seem to understand why backdoors are problematic.
If we require the government to prove the original crime in order to convict for refusing to testify then there is no point in making refusal to testify a crime, because any time they could prosecute for it they could already prove the original crime and don't need the testimony. The only way it helps the government is if they are also allowed to convict people who refuse to testify when being prosecuted for crimes they did not commit.
You might argue that an innocent person can be vindicated by telling the truth instead of refusing to testify, so innocent people don't need to refuse to testify. But that doesn't work when the government is playing "show me the man and I'll show you the crime." Everything you say can and will be used against you in a court of law and lying to the police is illegal. You have to be allowed to shut up or the government would be able to convict anyone they want just by compelling them to keep talking until the imperfect human in the fish bowl says something a court will accept as incriminating evidence.
So you want to make an exception for passwords. But if passwords are different than other testimony it's because we should be more protective of them. They're the ultimate fishing expedition. There is no relationship between the password and the crime. If there is no evidence of the crime under investigation whatsoever (perhaps because you didn't do it), they still get to see everything on your phone. Then they can charge you with whatever completely unrelated crime their fishing expedition uncovered and use parallel construction to bypass any restrictions on what the original evidence was supposed to be used for.
Moreover, it remains possible to investigate crimes even if you can't look at the contents of every suspect's device. You still have all the evidence supplied by the victim and witnesses and all the methods of traditional police work that existed before everyone started carrying around personal surveillance devices. Being able to force suspects to supply their passwords might help, but lots of things might help, and most of those things might help enough that it would at least slightly increase the percentage of guilty people convicted. That only tells you that some civil rights come at the cost of not convicting some guilty people. It doesn't imply that we should erase every one that does.
Roper: So now you'd give the Devil benefit of law!
More: Yes. What would you do? Cut a great road through the law to get after the Devil?
Roper: I'd cut down every law in England to do that!
More: Oh? And when the last law was down, and the Devil turned round on you — where would you hide, Roper, the laws all being flat? This country's planted thick with laws from coast to coast — man's laws, not God's — and if you cut them down — and you're just the man to do it — d'you really think you could stand upright in the winds that would blow then? Yes, I'd give the Devil benefit of law, for my own safety's sake.
Thumbprints are physical, so they don't get the same protections. It's kind of like having a physical key to a physical lock. It's not self-incrimination for law enforcement to take that key and use it in the lock.
Same with writing your passcode on a piece of paper. It's no longer a matter of self-incrimination if they find that and use it.
[1]: http://arstechnica.com/tech-policy/2014/10/virginia-judge-po...
https://www.washingtonpost.com/news/volokh-conspiracy/wp/201...
Basically, having to provide something in your mind, the passcode, is testimony, a finger print, much like a key, is not testimony.
> Developers have a cultural quirk where they believe that, e.g., "file sharing is not theft" / "manipulating a URL can't be a crime" / "laws about disclosing protected information invariably contain a public policy exception which comports to the temperament of the dev community" are axiomatic and thereby create an internally consistent legal system which fails to falsify those axioms but also fails to meaningfully resemble the legal system we actually operate in.
> This results in developers sincerely believe things like "Your Bitcoins are unprotected by the legal system because nobody can steal a number", which is a proposition that is absurd to the legal system as "JavaScript is not a programming language" is to a programmer.
(https://news.ycombinator.com/item?id=7367312)
In other words, no. There is—and should be—nothing special about computers.
Nothing special about computers? Okay. "Persons, papers, and effects" no longer means emails, computer files, or anything other than physical, tangible documents that existed when that law was drafted. I really don't think that's the world you want to live in, or the argument you really want to be making.
The fact that the legal system thinks there's "nothing special about computers" is the cause of a great deal of difficulties that should not exist in a sane world. This is a world with new concepts that did not exist when a lot of our laws were written, and it doesn't make much sense to presuppose that there is or even can be a 1:1 mapping between the tangible and the not, all of the time.
Can you point out where I did?
It's not, and your tone and sentiment indicates that you think it is.
Do you really believe that up until this week, "Happy Birthday" was someones 'property' ? Do you really believe that posting the ETA for city busses is a patentable innovation ?
Just because some legal thug perverts the definition of words (such as 'property' ) in the lawbooks does not change the way I regard them. Just like back when the books said that a black man was 3/5ths of a human being. Just because it says that in a book doesn't make it correct.
Also, you word it as if this is society's legal system. Society has about as much control over the legal system as peasant has over the dictates of their king. Unless you limit society only to the wealthy and well connected.
"Hmmm... I don't like gay minorities, let's hit them up for all the illegal things that everyone is doing, but which are still illegal."
Maybe there is a defense if the prosecutor says the above line exactly, but in general it allows for unfair application of the law. This quickly becomes 'don't piss off a cop/judge'.
Choose your own definitions of words if you like, but don't be surprised or outraged if the world doesn't share them.
I'm in favor, but for some reason this also makes me a little worried.
As for computing devices, aside from proprietary systems like Windows and Macs, do we not have reliable options that allow us to use uncompromised encryption?
Whats to stop app developers for embedding encryption packages or would they be forced to use compromised solutions?
Can you stop a person from building a secure line over a compromised medium, if that is even doable?
[0] Ok, I'm not concerned about it actually happening. The part of it that bothers me is the otherwise seemingly-sane individuals who agree with these backdoors. It's very difficult to discuss the issue with some of them because their interest in it is largely driven by emotions, specifically a desire for security and justice/revenge/control of criminal/terrorists/whatevers.
This seems also protect the policy from the temptation of doing stupid things that could lead to future lawsuits against them (like leaking photos of you drunken in a party, of from your girlfriend naked brushing her teeth and so...)
http://www.supremecourt.gov/opinions/13pdf/13-132_8l9c.pdf
http://scholarlycommons.law.northwestern.edu/cgi/viewcontent...
But we shouldn't have to rely on the law alone. We should be able to rely on technology to make it impossible to compel people to give up their most intimidate data. Computing devices have become an extension of the mind and no one on earth has a right to the contents of your mind.
The analogy I would use is a locked closet full of file boxes. If the government is certain that the files relating to a specific crime are in the closet, then you can be compelled to assist them in opening your closet or face an obstruction of justice charge. However if the police suspect you of a crime and suspect that you're the type of person who would keep the evidence in your locked closet that is not enough compel you to open the closet so the police can check up on their hunch.
In this case, I read it as the men are suspected of insider trading and the government believes that they would have used their cell phones to communicate about the deal and the phones contain evidence of such. There is no actual evidence that the phones were used and so they're not obstructing the police in obtaining evidence the police know is there, but rather preventing the police from poking around to see if the evidence exists at all.