I find it hilarious how often privacy advocates manage to forget that we've had this conversation before, and while the government can and has overstepped in many ways, lets not throw out the ability to investigate at all along the way.
I find it hilarious how often privacy advocates manage to forget that we've had this conversation before, and while the government can and has overstepped in many ways, lets not throw out the ability to investigate at all along the way.
Remember the "TSA locks" we're all required to use on our luggage at the airport? Nobody but the government was supposed to be able to unlock them. But now anyone who wants to ruffle through your luggage can get universal keys for all TSA locks. What happens when that same scenario plays out with your bank account, your company emails, or any online store you've made purchases from?
Backdoors don't work because yeah, it breaks the whole system. But not everything is encrypted with these companies, that's just plain.
There will always be some sort of secret only the government has access to, and once that secret is leaked it's game over.
All it's arguing, is to say "You don't have to encrypt literally every part of your system and delete the rest" a la what Snapchat suggests they're doing(though we don't have proof).
The only way the government can get the equivalent of a wire tap is if there is no end to end encryption. What police do not want is to need to go back to pre-telephone detective work where they need to determine the location at which the parties will communicate (with modern communications there are of course at least two locations) and compromise that location to spy on the supposed criminals.
I ask this because I'm curious whether you (and people in general) believe that hackability is the only obstacle to giving government access to personal data (with a warrant, of course), or if people would still be uncomfortable with such a system.
Personally, I think such a scheme would be a good compromise, but I'm not a crypto expert so I don't know if it's in any way feasible.
Key escrow came up back then though I don't think it included needing multiple keys in order to decrypt - not sure if that's mathematically possible or if there's another reason that never came up. I suppose to the government that's not much different than still needing to compel individuals for the key.
Your point about companies is interesting since things like iMessage could be MITM currently anyway to get unencrypted content for government requests. I think most people don't necessarily trust the company behavior here though and given the government's recently revealed behavior with National Security Letters and secret, massive, unwarranted data collection I don't think they should get a pass. I'd rather side on the power structure unable to collect some of the information even if they're unable to investigate.
I think fundamentally introducing multiple ways to get keys takes a secure system and makes it insecure - the access no longer rests on one individual's knowledge. In general I think that's a bad idea - it also doesn't prevent people who want to actually encrypt their information from doing so (it just harms the regular public and dumber criminals).
As a matter of interest Shamirs Secret Sharing algorithm (https://en.wikipedia.org/wiki/Shamir's_Secret_Sharing) is quite nice in that respect. The "secret" would be the decryption key. Using Shamirs Secret Sharing algorithm you could split the key into two so you would need both parts in order to work out the decryption key. The government could have a part. The company could have another. Only when both were combined could anyone work out the decryption key.
This would mean neither the company nor the government could decrypt messages until they work together - and therefore reduce the risk of hackers and rogue employees. It wouldn't break the encryption with dangerous backdoors but would allow the authorities to quickly gain access when needed for a specific investigation.
I doubt anyone would ever implement anything like that since it would be (slightly more) complex and you would have to trust that the decryption parts are valid. But I thought I would just mention it in case anyone else might find that algorithm as interesting as I do.
If you have a government entity routinely breaking into companies and taking over access to things (targeting sysadmins) then the scheme doesn't work very well. I think most of the argument behind encryption falls on this idea that it either is secure (no backdoors) or it isn't. You have a spectrum of insecure things you can do that are arguably better than nothing, but they're not secure.
Traditional policework goes a very, very long way, and it's time to admit that the terrorism angle is too overblown and intentionally abused to take seriously anymore.
Ultra-narrowly targeted, ultra limited duration, warrant-required wiretaps which are disclosed as evidence in full during court trial are what is acceptable when exhaustion of traditional methods hasn't closed the case. That is the standard we should work from.
And don't forget:
- number of deaths from acts of domestic terrorism: 36
- number of deaths–homicide, suicide, and accidental–caused by firearms: 316,545
(in a decade, link: http://magazine.good.is/articles/president-obama-gun-deaths-...)
It's hilarious how some people forget what really counts (as in pain and sorrow) and where the priorities should be.
Having a reasonable way to read that stuff(WITHOUT USING A BACKDOOR. I don't want weaker crypto just for this- but businesses hosting this stuff always have their proprietary ways of handling things) is just a continuation of previous law.
The difference here is that the government wants vastly more access in the digital world than they have in the analog world. It's like asking all safe makers to include a secret combination, unknown to the safe's owner, that can also be used to unlock the safe.
You don't backdoor the algorithm. You backdoor the use of the algorithm--except it is more of a front door than a back door. For instance, when the device encrypts data with a symmetric cipher, encrypt a copy of the symmetric key via a public key cipher using the FBI's public key.
Variant: split the symmetric cipher key into N shares using a secret sharing algorithm, and save each share encrypted with a different public key. Include public keys from major law enforcement agencies (FBI, Interpol), and major civil rights or human rights organizations (ACLU, EFF). Design the secret sharing so that to recover the symmetric key, you need key shares from two major law enforcement agencies and from two of the civil rights organizations.
If we are using the secret sharing variant, then it means that during the time between the leak and the time the device manufacturers push out an update to replace that key and re-encrypt the appropriate shares with the new key someone who seizes a phone and wants to decrypt it only needs the approval of one major police agency and two civil rights organizations instead of two major police agencies and two civil rights organizations.
If we are not using that variation, then it means that until a new key goes out in an update anyone who seizes your phone (and who has the leaked key) can decrypt it. One way to protect against this would be for the device to have a command that erases the saved encrypted symmetric keys. This command would require that you show it that you have a copy of the corresponding private key before it erases the encrypted keys.
Offhand the only ones I remember are D-Link's leak of a code signing key this year and AMI's leak of a BIOS signing key a couple years ago. I've probably forgotten some.
Keys of this value are generally not stored online, and are often split using a secret sharing system among several people.
It's not hard to set up a system where all of the decryption of the encrypted symmetrical keys of seized phones takes place on a computer that has no network connection and no interface to the outside world other than CD-RW discs [1].
Of course just because there are ways to manage the private key and its use in such system that are arbitrarily safe that doesn't mean that the FBI would actually handle their key properly. If they do lose control of it, it would be bad.
My point, though, was just to illustrate that it is not the case that providing warrant access requires putting in a backdoor that completely opens up the system to anyone who knows about the backdoor and then hoping to keep knowledge of the backdoor hidden.
Also note I'm only trying to design this for data stored on phones and tablets, not for communication systems or servers.
[1] Thumb drives would be more convenient, but they contain electronics and interface via a port that is very hackable.
And that is also a conversation we've had before. There is no warrant you can get to force a suspect to testify against himself.
Though, it's cute that you think these "conversations" are meaningful. If the American government thinks you're too interesting to not know more about, they'll black-bag you and ship you off to a secret CIA dungeon where you'll be tortured for the rest of your life. Even if you end up being held without charge in a cushy place like Guantanamo, you'll never be released because you were held without charge and that makes you a terrorist.
I find it hilarious how surveillance advocates manage to forget that your government does not respect rule of law, it rules by law. It is the law.
You also can't get a warrant to peer into the other unbreakable data store - a suspect's mind. If there were such a technology would it be ok for it to be warrantable or should some things just actually be private?