Obama Encryption Policy Rejects Laws Mandating Backdoors
eff.org
eff.org
FTA: "Instead, the Post reports, the “administration will continue trying to persuade companies that have moved to encrypt their customers’ data to create a way for the government to still peer into people’s data when needed for criminal or terrorism investigations.”
While eschewing attempts to legislatively mandate that tech companies build backdoors into their services, the president is continuing the status quo – that is, informally pressuring companies to give the government access to unencrypted data."
Status quo is that the government doesn't respect the privacy of its citizens.
"Obama 'will not —for now— call for legislation requiring companies to decode messages for law enforcement.'"
The point here is that where we have device and service providers like Apple and Google and whoever-just-bought-LastPass where we do trust them to encrypt our info, the government won't be making rules that compel them to undo that work.
If you didn't trust Google and Apple to begin with, the government compulsion would be meaningless anyway.
I find it hilarious how often privacy advocates manage to forget that we've had this conversation before, and while the government can and has overstepped in many ways, lets not throw out the ability to investigate at all along the way.
Remember the "TSA locks" we're all required to use on our luggage at the airport? Nobody but the government was supposed to be able to unlock them. But now anyone who wants to ruffle through your luggage can get universal keys for all TSA locks. What happens when that same scenario plays out with your bank account, your company emails, or any online store you've made purchases from?
Backdoors don't work because yeah, it breaks the whole system. But not everything is encrypted with these companies, that's just plain.
There will always be some sort of secret only the government has access to, and once that secret is leaked it's game over.
All it's arguing, is to say "You don't have to encrypt literally every part of your system and delete the rest" a la what Snapchat suggests they're doing(though we don't have proof).
The only way the government can get the equivalent of a wire tap is if there is no end to end encryption. What police do not want is to need to go back to pre-telephone detective work where they need to determine the location at which the parties will communicate (with modern communications there are of course at least two locations) and compromise that location to spy on the supposed criminals.
I ask this because I'm curious whether you (and people in general) believe that hackability is the only obstacle to giving government access to personal data (with a warrant, of course), or if people would still be uncomfortable with such a system.
Personally, I think such a scheme would be a good compromise, but I'm not a crypto expert so I don't know if it's in any way feasible.
Key escrow came up back then though I don't think it included needing multiple keys in order to decrypt - not sure if that's mathematically possible or if there's another reason that never came up. I suppose to the government that's not much different than still needing to compel individuals for the key.
Your point about companies is interesting since things like iMessage could be MITM currently anyway to get unencrypted content for government requests. I think most people don't necessarily trust the company behavior here though and given the government's recently revealed behavior with National Security Letters and secret, massive, unwarranted data collection I don't think they should get a pass. I'd rather side on the power structure unable to collect some of the information even if they're unable to investigate.
I think fundamentally introducing multiple ways to get keys takes a secure system and makes it insecure - the access no longer rests on one individual's knowledge. In general I think that's a bad idea - it also doesn't prevent people who want to actually encrypt their information from doing so (it just harms the regular public and dumber criminals).
As a matter of interest Shamirs Secret Sharing algorithm (https://en.wikipedia.org/wiki/Shamir's_Secret_Sharing) is quite nice in that respect. The "secret" would be the decryption key. Using Shamirs Secret Sharing algorithm you could split the key into two so you would need both parts in order to work out the decryption key. The government could have a part. The company could have another. Only when both were combined could anyone work out the decryption key.
This would mean neither the company nor the government could decrypt messages until they work together - and therefore reduce the risk of hackers and rogue employees. It wouldn't break the encryption with dangerous backdoors but would allow the authorities to quickly gain access when needed for a specific investigation.
I doubt anyone would ever implement anything like that since it would be (slightly more) complex and you would have to trust that the decryption parts are valid. But I thought I would just mention it in case anyone else might find that algorithm as interesting as I do.
If you have a government entity routinely breaking into companies and taking over access to things (targeting sysadmins) then the scheme doesn't work very well. I think most of the argument behind encryption falls on this idea that it either is secure (no backdoors) or it isn't. You have a spectrum of insecure things you can do that are arguably better than nothing, but they're not secure.
You also can't get a warrant to peer into the other unbreakable data store - a suspect's mind. If there were such a technology would it be ok for it to be warrantable or should some things just actually be private?
You don't backdoor the algorithm. You backdoor the use of the algorithm--except it is more of a front door than a back door. For instance, when the device encrypts data with a symmetric cipher, encrypt a copy of the symmetric key via a public key cipher using the FBI's public key.
Variant: split the symmetric cipher key into N shares using a secret sharing algorithm, and save each share encrypted with a different public key. Include public keys from major law enforcement agencies (FBI, Interpol), and major civil rights or human rights organizations (ACLU, EFF). Design the secret sharing so that to recover the symmetric key, you need key shares from two major law enforcement agencies and from two of the civil rights organizations.
If we are using the secret sharing variant, then it means that during the time between the leak and the time the device manufacturers push out an update to replace that key and re-encrypt the appropriate shares with the new key someone who seizes a phone and wants to decrypt it only needs the approval of one major police agency and two civil rights organizations instead of two major police agencies and two civil rights organizations.
If we are not using that variation, then it means that until a new key goes out in an update anyone who seizes your phone (and who has the leaked key) can decrypt it. One way to protect against this would be for the device to have a command that erases the saved encrypted symmetric keys. This command would require that you show it that you have a copy of the corresponding private key before it erases the encrypted keys.
Offhand the only ones I remember are D-Link's leak of a code signing key this year and AMI's leak of a BIOS signing key a couple years ago. I've probably forgotten some.
Keys of this value are generally not stored online, and are often split using a secret sharing system among several people.
It's not hard to set up a system where all of the decryption of the encrypted symmetrical keys of seized phones takes place on a computer that has no network connection and no interface to the outside world other than CD-RW discs [1].
Of course just because there are ways to manage the private key and its use in such system that are arbitrarily safe that doesn't mean that the FBI would actually handle their key properly. If they do lose control of it, it would be bad.
My point, though, was just to illustrate that it is not the case that providing warrant access requires putting in a backdoor that completely opens up the system to anyone who knows about the backdoor and then hoping to keep knowledge of the backdoor hidden.
Also note I'm only trying to design this for data stored on phones and tablets, not for communication systems or servers.
[1] Thumb drives would be more convenient, but they contain electronics and interface via a port that is very hackable.
And don't forget:
- number of deaths from acts of domestic terrorism: 36
- number of deaths–homicide, suicide, and accidental–caused by firearms: 316,545
(in a decade, link: http://magazine.good.is/articles/president-obama-gun-deaths-...)
It's hilarious how some people forget what really counts (as in pain and sorrow) and where the priorities should be.
Having a reasonable way to read that stuff(WITHOUT USING A BACKDOOR. I don't want weaker crypto just for this- but businesses hosting this stuff always have their proprietary ways of handling things) is just a continuation of previous law.
The difference here is that the government wants vastly more access in the digital world than they have in the analog world. It's like asking all safe makers to include a secret combination, unknown to the safe's owner, that can also be used to unlock the safe.
Traditional policework goes a very, very long way, and it's time to admit that the terrorism angle is too overblown and intentionally abused to take seriously anymore.
Ultra-narrowly targeted, ultra limited duration, warrant-required wiretaps which are disclosed as evidence in full during court trial are what is acceptable when exhaustion of traditional methods hasn't closed the case. That is the standard we should work from.
And that is also a conversation we've had before. There is no warrant you can get to force a suspect to testify against himself.
Though, it's cute that you think these "conversations" are meaningful. If the American government thinks you're too interesting to not know more about, they'll black-bag you and ship you off to a secret CIA dungeon where you'll be tortured for the rest of your life. Even if you end up being held without charge in a cushy place like Guantanamo, you'll never be released because you were held without charge and that makes you a terrorist.
I find it hilarious how surveillance advocates manage to forget that your government does not respect rule of law, it rules by law. It is the law.
> Partial Victory: Obama Encryption Policy Rejects Laws Mandating Backdoors, But Leaves the Door Open for Informal Deals
Compared to:
> Obama Encryption Policy Rejects Laws Mandating Backdoors
It also doesn't sound like a full on rejection, as new information might cause him to change his stance:
> “will not —for now—call for legislation requiring companies to decode messages for law enforcement.”
Really the only reason to pass policy against policy in this case is to score political points with the Hacker News interest group, which is a pretty niche constituency...
This is about what's cryptographically possible and what isn't. I don't frankly care if anyone respects my privacy, what I want is the ability to shut adversaries out, period, using math.
This decision means companies can say 'no'. That's a win, because it lets the math be possible in the first place.
1. Political (use money, shame, votes, and threats, praying that these things still work to effect change)
2. Technological (use encryption, praying technological solutions are implemented evenly and properly and that there are no back doors)
3. Violence
1 and 2 are the workable strategies, and they only work when practiced together. Currently we are seeing the government's #1 try to trample on #2, frequently using #3. If we can whittle a bit more respect for #2 using #1, it'll make the rest of the journey back to liberal democracy easier. Political changes happen through shifted mindsets.
The only way to stop someone from doing something is to make them unable to do it. That's not solved through shame or appeal to emotion, because the people doing the bad things aren't going to express emotions.
Keep trying to shame them, and you'll simply fail. We need to build something they can't break.
"Obama Encryption Policy Rejects Laws Mandating Backdoors"
The Obama administration is rejecting mandated backdoors. That's what the headline says and it's completely correct.
The rest of your comment is correct; they aren't rejecting backdoors, just rejecting making them mandatory.
* The FBI-NSA-etc. axis already tried to ban nonescrowed crypto. This was in 1997, when far fewer products relied on it, far fewer people used the Internet, and far fewer groups mobilized to oppose it. If even that effort failed, this one was likely to fail as well.
* Excerpt from that 1997 proposal, which was actually approved(!) by a House of Representatives committee: "It shall be unlawful for any person to manufacture for distribution, distribute, or import encryption products intended for sale or use in the United States, unless that product..." http://thomas.loc.gov/cgi-bin/cpquery/T?&report=hr108p4&dbna...
* I disclosed in 2012 that the FBI had drafted a proposed law to require backdoors; that legislation was never introduced, even as a placeholder. My 2012 article: http://www.cnet.com/news/fbi-we-need-wiretap-ready-web-sites... Of course the FBI's bill could be kept in reserve to become Patriot Act 2.0, just like the FBI-NSA-etc. axis had EPPSCA in reserve, which morphed into Patriot Act 1.0 a month after the 9/11 attacks, as I wrote about here: http://www.cnet.com/news/how-bin-laden-and-911-attacks-shape...
* If the legislative approach is now off the table, as the WashPost piece indicates, look for the FBI-NSA-etc. axis to try more creative approaches. "Oh, you want that $2 billion government contract? You want your new device to be FIPS 140-2 certified? How about that merger or FTC antitrust review? Environmental reviews? Trade? Taxes? It sure would be a shame if things didn't go your way. Maybe you can help us and we'll help you..."
This is why it's worth supporting groups like EFF (I donated last year and need to again before the end of this year). They provide a moral argument that counters that of the Washington establishment--and also provides guidance for tech firms when they're faced with challenges like those above.
How can we know that NSL's aren't being used right now to "persuade" or coerce companies to cooperate? Who needs legislation when you effectively don't have to reveal anything?
Is it optimistic to think that most of the tech community at least should recognize the significance of this? Even if you doubt its effect on real policy.
Disclosure: I work in the netsec industry and only signed this because HN brought it to my attention in the rare spare moments between my daily tasks. To use an analogy, I feel like I can't worry about putting out the forest fire if my house is already on fire in the midst of it. At the same time, I'm throwing money at someone that says they'll help me free up more time to do the forest fire fighting. We'll see if I've made a grave mistake in how I prioritize things.
Meet the new boss, same as the old boss.
The status quo can be improved but it's a process of beating the system and the people in it until they stop resisting, not choosing better ones or convincing them you're in the right.
You want transparency? Lead by example.
If you are one of these companies that are informally cooperating with the government on this, please state so publicly, in the signup process and by message to current users, so that we can avoid using your services now, or at least when it's discovered later if you weren't honest about it up front.
As of [date], we have not received any legal process or demand from any federal, state, or local government that includes a gag order. We have received no National Security Letters, civil subpoenas, search warrants, Foreign Intelligence Surveillance Act orders, grand jury subpoenas, or any other form of compulsory process accompanied by a gag order.
As of [date], we have received no legal orders requiring us to monitor users' future activities or to modify our service.
If we do receive any form of compulsory process from any government entity, we will do our best to ensure that our users' legal rights and privacy rights under the Fourth Amendment to the U.S. Constitution are protected. That includes challenging overly broad orders in court.
It is still valid, I'm happy to say, for [date] values of today.
This should not be taken as legal advice, YMMV, yadda yadda.