What he's questioning is whether the government has the authority to conscript a third party (Apple) and force them to execute the warrant.
What he's questioning is whether the government has the authority to conscript a third party (Apple) and force them to execute the warrant.
In this case, it has come up that Apple owns the software on your phone, and grants you a temporary license to use it. You do not have ownership of the copy of iOS, Apple does. The government has been attempting to use that to their advantage.
In which case you make the tool require anonymous treshold signatures in where at least m of n technicians must issue the order.
So that if n-(m+1) or more technicians refuse to cooperate, the request fails and you don't know who is innocent and who made the choice to break it.
Unless of course everybody are forced to hand over their keypairs and all - in which case you go yet another step further and give them canary keys which then cause a lock-down (the HSM could even wipe its secret keys completely in this case), and you still don't know who did it.
The law doesn't have to - and never does - respect clever CS constructions.
I'm thinking more of the situation that you locked the safe and also lost the key prior to its contents being declared evidence and that you cannot physically now open it.
I am not a lawyer. I am definitely not your lawyer!
So the starting premise is that the device in question is already under the control of LE, a group of individuals has the ability to unlock the device (if they provide the correct keys), and they are being legally compelled to do so. In that specific situation, if anyone "defects" (provides the canary key), it's a crime, and everyone can go down for conspiracy, even if they themselves provided a valid key (which, in this scenario, is something we're assuming couldn't be proven anyway) and even if they never intended to break the law. That's the key part of a conspiracy prosecution - it doesn't matter which participant actually committed the crime, all the participants can be tried as if they were the "trigger-man".
TBH I'm not up for tracking all this down in the US legal code (got stuff to do, and IANAL), but here's the statute in the California penal code:
http://codes.findlaw.com/ca/penal-code/pen-sect-182.html
Note, in particular (heavily snipped for brevity/relevance):
> (a) If two or more persons conspire: [snip] (5) To commit any act injurious to the public health, to public morals, or to pervert or obstruct justice, or the due administration of the laws.
> They are punishable as follows: [snippity snippity snip....] When they conspire to commit any other felony, they shall be punishable in the same manner and to the same extent as is provided for the punishment of that felony.
There's no provision that the conspirators (or the prosecution) know which of their number actually committed the crime.
None of this would be relevant for HSMs on devices that aren't part of an investigation, or in general, any situation except one where a group of people are being legally compelled to enable access to evidence.
The bigger-picture point is just that using a split-key mechanism to give plausible deniability to each individual key-holder doesn't actually pose any problem for the criminal justice system. Legal authority would be pretty meaningless if it could be foiled by crypto gimmicks. IRL, it's "haha, very clever, now the HSM gets unlocked or all of you go down for obstruction."
edit: fixing formatting of the quoted blocks
> (a) If two or more persons conspire: [snip] (5) To commit any act injurious to the public health, to public morals, or to pervert or obstruct justice, or the due administration of the laws.
This entire section would not apply, because that was never the intent of any participant during setup - it is a hacking protection fail-safe. They wanted to comply with the law, but after-the-fact some techs defected due to not trusting law enforcement.
What? No. The judge would be ordering Apple. A whole separate case would need to be brought ordering specific people.
Let's game it through:
1. Tim Cook, following judges order, orders the engineers with the knowledge to unlock the device.
2. The engineers refuse Cook's order. He reports this to the judge.
4. Judge has two options: Order Cook to threaten to fire said employees, or individually order employees to comply. Most likely the former is legally untenable. He thus is forced to do the latter.
I don't believe a judge would or even could go that far, except perhaps in times of war.