Apple unlock: Judge compares request to execution order
bbc.com
bbc.com
I deeply hate the fact that anybody thinks anything on my personal devices belongs to them. I think my devices should fall under the inviolability of the physical body and that decrypting them is akin to forcing me to testify against myself.
I do realize how hypocritical I sound carrying an Android device (Googles customers are the advertisers) but I can be a bit idealistic and pragmatic at the same time, can't I?
>My main theme is the extension of the nervous system in the electric age, and thus, the complete break with five thousand years of mechanical technology. This I state over and over again. I do not say whether it is a good or bad thing. To do so would be meaningless and arrogant.
>In the electric age, when our central nervous system is technologically extended to involve us in the whole of mankind and to incorporate the whole of mankind in us, we necessarily participate, in depth, in the consequences of our every action. It is no longer possible to adopt the aloof and dissociated role of the literate Westerner.
>Instead of tending towards a vast Alexandrian library the world has become a computer, an electronic brain, exactly as an infantile piece of science fiction. And as our senses have gone outside us, Big Brother goes inside. So, unless aware of this dynamic, we shall at once move into a phase of panic terrors, exactly befitting a small world of tribal drums, total interdependence, and superimposed co-existence.
>The inner trip is not the sole prerogative of the LSD traveler; it’s the universal experience of TV watchers.
-McLuhan
> Does TV encourage, or even induce, schizophrenia? Or does it create a separate reality in conjunction with our minds, something that is neither totally our inner life nor totally TV. The networks might call that programming.
- Pat Cadigan, from her forward to her short story "Patterns"
> Modern cell phones are not just another technological convenience. With all they contain and all they may reveal, they hold for many Americans "the privacies of life." The fact that technologies now allow an individual to carry such information in his hand does not make the information any less worth of the protection for which the Founders fought.
- Chief Justice Robers, in the majority opinion of Riley v California
https://books.google.com/books?id=7K7rKIWaXXIC&pg=PR59&lpg=P...
I would argue that it's a difference in quantity which produces a difference in kind. When the "papers" in question contain e.g. a complete history of your location for the last four years, along with all of your communications to everyone you know, any search of those papers is by definition open-ended.
The same principle already applies both in the UK and USA to physical searches of your person. If you're being searched for a weapon then patting down is a sufficient search, a strip search is not.
I don't think that's true. Anyone who kept a personal diary back in 1776 probably recorded more information about their activities and thoughts than an ordinary smartphone user today. And the detailed letters many people wrote each other back then probably reveal a lot more in the way of private thoughts than peoples' text messages today.
Undoubtedly the average person records more today than the average person in 1789. But that does not mean that more detailed record-keeping would have been beyond what people back then could have anticipated. Given the phenomenally detailed records we have from some people at that time, I think it was well within the contemplation of the framers that getting a warrant for someone's desk drawer could reveal extensive personal information.
Not to volleyball this, but I don't think that's true. Any information in a personal diary is there because it was intentionally, explicitly entered there (even if with the expectation that it would remain private). There is a lot of information on most people's phones that they have not intentionally, explicitly put there.
Remember the question we are discussing: could people in 1789 have anticipated the kind of invasions of privacy searches of smartphones enable today? Given the kind of detailed records some people back then kept, not just bland metadata but detailed accountings of their thoughts, I think the answer is "yes."
We are still a long way from smartphones automatically capturing the kind of private thoughts people choose to write down (back then as now).
You're quite right, but so too are one's personal papers (or they were, anyway, back when people only had paper), and there is a process — the warrant process — for legally obtaining access to those papers.
More important, though, it should not be possible for a third party to grant a second party access to your personal devices. If Apple have no way to break into your device without your permission, then you are secure.
> I think my devices should fall under the inviolability of the physical body and that decrypting them is akin to forcing me to testify against myself.
Agreed — but do note that that right is somewhat more circumscribed than your or I like to imagine. And in this case, they are requiring a third party to decrypt the device, not you.
They should make it clear from day one that if this doesn't pass, they will oppose the bill - unlike what they did with the USA Freedom Act, where they compromised, and compromised, and compromised to pass..."something".
I should note that Microsoft already supports something like that (warrant directly to the customer), but only for their corporate customers, not for their individual customers (last paragraph before "A new path forward"):
http://blogs.microsoft.com/on-the-issues/2015/10/20/the-coll...
If only that attitude were documented in the most basic law of the U.S., clearly defining the strictly delimited powers of the government. Maybe something like this:
"The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized."
ETA: Yes, I know the government has a warrant in this case. The judge is considering the question of whether that warrant is reasonable.
Indeed. I agree that such warrants should be deemed unreasonable. Unless the government can meet the criteria of "describing the place to be searched", going through a phone is more akin to a fishing expedition.
There's the photo gallery, downloads, multiple social networking apps, SMS, maps, IM, search history, configurations, app list, games, note taking apps, etc...
What he's questioning is whether the government has the authority to conscript a third party (Apple) and force them to execute the warrant.
In which case you make the tool require anonymous treshold signatures in where at least m of n technicians must issue the order.
So that if n-(m+1) or more technicians refuse to cooperate, the request fails and you don't know who is innocent and who made the choice to break it.
Unless of course everybody are forced to hand over their keypairs and all - in which case you go yet another step further and give them canary keys which then cause a lock-down (the HSM could even wipe its secret keys completely in this case), and you still don't know who did it.
The law doesn't have to - and never does - respect clever CS constructions.
I'm thinking more of the situation that you locked the safe and also lost the key prior to its contents being declared evidence and that you cannot physically now open it.
I am not a lawyer. I am definitely not your lawyer!
So the starting premise is that the device in question is already under the control of LE, a group of individuals has the ability to unlock the device (if they provide the correct keys), and they are being legally compelled to do so. In that specific situation, if anyone "defects" (provides the canary key), it's a crime, and everyone can go down for conspiracy, even if they themselves provided a valid key (which, in this scenario, is something we're assuming couldn't be proven anyway) and even if they never intended to break the law. That's the key part of a conspiracy prosecution - it doesn't matter which participant actually committed the crime, all the participants can be tried as if they were the "trigger-man".
TBH I'm not up for tracking all this down in the US legal code (got stuff to do, and IANAL), but here's the statute in the California penal code:
http://codes.findlaw.com/ca/penal-code/pen-sect-182.html
Note, in particular (heavily snipped for brevity/relevance):
> (a) If two or more persons conspire: [snip] (5) To commit any act injurious to the public health, to public morals, or to pervert or obstruct justice, or the due administration of the laws.
> They are punishable as follows: [snippity snippity snip....] When they conspire to commit any other felony, they shall be punishable in the same manner and to the same extent as is provided for the punishment of that felony.
There's no provision that the conspirators (or the prosecution) know which of their number actually committed the crime.
None of this would be relevant for HSMs on devices that aren't part of an investigation, or in general, any situation except one where a group of people are being legally compelled to enable access to evidence.
The bigger-picture point is just that using a split-key mechanism to give plausible deniability to each individual key-holder doesn't actually pose any problem for the criminal justice system. Legal authority would be pretty meaningless if it could be foiled by crypto gimmicks. IRL, it's "haha, very clever, now the HSM gets unlocked or all of you go down for obstruction."
edit: fixing formatting of the quoted blocks
> (a) If two or more persons conspire: [snip] (5) To commit any act injurious to the public health, to public morals, or to pervert or obstruct justice, or the due administration of the laws.
This entire section would not apply, because that was never the intent of any participant during setup - it is a hacking protection fail-safe. They wanted to comply with the law, but after-the-fact some techs defected due to not trusting law enforcement.
What? No. The judge would be ordering Apple. A whole separate case would need to be brought ordering specific people.
Let's game it through:
1. Tim Cook, following judges order, orders the engineers with the knowledge to unlock the device.
2. The engineers refuse Cook's order. He reports this to the judge.
4. Judge has two options: Order Cook to threaten to fire said employees, or individually order employees to comply. Most likely the former is legally untenable. He thus is forced to do the latter.
I don't believe a judge would or even could go that far, except perhaps in times of war.
In this case, it has come up that Apple owns the software on your phone, and grants you a temporary license to use it. You do not have ownership of the copy of iOS, Apple does. The government has been attempting to use that to their advantage.
The majority of requests are made because someone suspected of a crime (pick any crime: fraud, possession of child pornography, drug dealing) - and they believe there to be evidence on the device.
If we prevented legal authorities from accessing data on your phone, then in theory a peadophile would only have to ensure he/she downloads illegal images to their phone to ensure they cannot be caught.
---
The reason we have warrants is to ensure there is a second layer to verify that a search is proportionate. Obtaining information from a phone should certainly require a warrant issued by a judge; but it certainly should not be completely unobtainable.
However, it doesn't require much of an imagination to think of other scenarios:
* Keeping records of drug sales on a phone. * Messaging a hitman to carry out a murder. * Recording days and times of homes being empty in preparation for a break in.
It's a question of where we draw the line. If we don't allow a judge to issue a search warrant for a phone where there is reasonable suspicion of illegal activity - why should we allow a judge to issue a warrant to search a car/property/paper-work?
Of course that completely oversteps the line in the other direction though. Conviction rates for many crimes would drop through the floor if the legal authorities have no way of obtaining evidence.
Given how powerful smart phones have become and you come run a criminal enterprise solely through your phone, it is reasonable to expect that the police with a proper warrant would be able to inspect your phone.
In fact... for a pretty reasonable sum, I could build a sub-dermal implant beneath the skull with many GBytes of storage that is wirelessly powered and supports USB-like data rates. (See profile.) So this isn't an academic argument.
In reality, I think you could make a pretty reasonable case that my lab notebooks (whether paper or electronic) are just a "more accurate version of my wetware memories." I'm not sure I understand why this "brain extension" isn't afforded more protections accordingly.
I appreciate that this notion wasn't explicitly spelled out in the constitution -- these advances are REALLY new from a historical perspective. But I would wager: The laws will likely need to change.
"The Right to Be Silent" , The Rape of the Mind: The Psychology of Thought Control, Menticide, and Brainwashing by Joost A. M. Meerloo, 1956
Look up NSA and loveint, and other such abuses of intel. As well as the age old industrial espionage. Is the majority of it really aimed towards protection?
Only it ensures no such thing. If the police have probable cause to suspect you of a crime then they'll have access to your phone metadata, financial records, etc. With a warrant they can put a microphone and camera in your house. There are ten thousand other ways to convict someone who is actually guilty.
I think it's fine to issue a legitimate warrant for the information stored on someone's phone. But then it's up to the authorities to execute that warrant. If the phone is so well protected that the authorities can't execute their warrant, too bad so sad for them. Just because there's no equivalent of a battering ram for digital devices doesn't mean manufacturers should be required to deliberately cripple their products.
I believe Apple should be required to unlock this phone (with reasonable compensation for their efforts), but this is going to be a limited thing as the older OSes fade, since the newer ones can't be unlocked even by them.
I see this repeated over and over again, but that's simply not true. The problem is that people treat such relationships as if it's a zero sum game.
But to make an analogy and please bear with me, if you look in nature at a natural food-chain, the relationship between the carnivore and the herbivore and then between the herbivore and the grass that it eats is not zero-sum at all, being actually a synergetic relationship, continuously creating value (in nature this means life). It's a wonderful relationship, with the grass storing sun energy into calories that can be consumed. And the carnivore wouldn't survive without that grass, as no grass means no herbivores left to be eaten. And the herbivores themselves depend on the existence of a natural enemy, otherwise they'd breed too much and quickly deplete their food source. Now skipping over the cultural taboos we have over the relationship between hunter and pray, there's something to be said about the synergies in a food-chain that apply to economic systems just as well.
You can say that Google's customers are the advertisers and by that implying that its users are actually the product that they are selling. But the truth is more complex than that. Because users are not produced on an assembly line, like Apple is producing its hardware. Users have a mind of their own and can install ad-blockers or can switch to other products and services if you piss them off. For these reasons users are not a commodity. And so the fact is that users along with advertisers are Google's customers, being in a synergetic relationship. Of course, if money change hands that's even better and note Google's forays into the subscription based model, along with Google Apps or YouTube Red.
And by your logic, Apple's customers are the carriers and the app developers, which is actually true but note that the interests of the carriers and of app developers can also be in conflict with the interests of Apple's users. Have you noticed that your carrier can disable your right to create a Wifi hotspot with your iPhone? Because I did.
Back to Google, their genius is that they recognized this synergy and played in the interests of everybody. Well, at least in the times of Eric Schmidt. It all went downhill when Vic Gundotra led the Google+ effort. I don't know what's this tendency to hire management from Microsoft, but along with the likes of Stephen Elop I'm seeing a pattern. Anyway, lately I've been dissatisfied with Gmail's support for standards, so I decided that I don't want to encourage a monoculture and switched to FastMail. I hope they'll return to their strategy from the days of Eric Schmidt, because if trust is lost amongst us techies, then it's really hard to regain it - see Microsoft - and us techies are quite an influential bunch.
Well, there's a pretty big difference between non-destructively copying someone's phone, and taking the phone apart and unsoldering the memory chip.
Second, if the DoJ starts doing that, the next obvious step for Apple is to put the encryption key in a hardware security module that the DoJ can't crack. This is an arms race that they can't possibly win.
If you use a password as a key to encrypt data on the device, no amount of hardware or software access is going to reveal the data.
Cracking of the passcode must be done "on device" unless someone can extract the UID from the Secure Enclave. Additionally, any device using an A7 or newer has incorrect passcode rate limits enforced by the Secure Enclave as well.
As to what is different between iOS7 vs iOS8/9, I'm not entirely sure. Matthew Green speculates[1] that they may load special firmware that bypasses the "lock" screen which is purely a UI hack. Apparently before iOS8 only a subset of user data was being encrypted compared to what is being encrypted now.
[0] https://www.apple.com/business/docs/iOS_Security_Guide.pdf
[1] http://blog.cryptographyengineering.com/2014/10/why-cant-app...
1. re encryption:
> Apparently before iOS8 only a subset of user data was being encrypted compared to what is being encrypted now.
Which leaves my question unanswered: in that case the government could still unsolder the flash chip and access that data. Your link [1] mentions that this would include pictures and SMS messages, which is probably what they were after.
2. Custom firmware from Apple will help to access encrypted parts since it would allow to run the OS under the cracker's control, who then only needs to brute force the password and not the UID. According to [1] this is still slowed down to 12.5 attempts per seconds (80 ms) and newer iPhone hardware additionally contains hardware enforced rate or number of guesses limits.
Edit: custom firmware would of course also help in case 1 in the sense that it makes it unnecessary to unsolder the flash. But my estimate for the effort needed to do the latter would be around USD 1000 if done exceptionally, perhaps USD 100 if done often enough. I wonder if Apple's unlocking service would be any cheaper. So perhaps the reason it's not being done is psychological (Apple complying is offloading the question whether it's OK), or the law, or worries about the constitution.
If you take these kinds of cases and carry them to their logical conclusion, there is nothing that will bar the government from using mind reading technology to read your mind even if it is just to assess your "mental state" and preemptively remove you from society, monitor you on a constant basis, set up traps and tricks to ensnare you, etc. The worst kind of enemy is the enemy saboteur from within, which the US and other governments are starting to become.
I guess this goes deeper than just the searching of the phone. Is Apple not allowed to ever change its mind, on anything?
-Marshall McLuhan
As to whether the fourth amendment applies - that's the question they're answering in court. Is this a search, in which case the government can compel Apple to disclose useful information, or is the DoJ asking for Apple to do something on their behalf?
The Apple extension would be that the govt can force unlocking by Apple (since they have a key) but not by you. All the more you reason to make it technically impossible ...
But the recent ones make it impossible, yeah
If they appeal, it'll go to a higher court which could overrule the lower court. If a higher court refuses to hear the case (as the supreme court often does), then the ruling of the highest ruling court stands.
The law is vague because current laws were written by people who didn't understand the tech or were writing to govern or regulate a different technology entirely.
So the real question is when does this happen? Will Congress get involved at the behest of the Justice Department and mandate access? If so, how long before phone companies are required to lock out devices running a version of the software that does not comply?
I still want an erase/panic code for my phone, both through pass phrase and touch sensor. That way I could hand over an unlocked phone that is effectively returned to manufacturer specs.
The powers that be would be highly unamused. It would make for some interesting case law.