How not to report on the encryption ‘debate’
cjr.org
cjr.org
“metadata absolutely tells you everything about somebody’s life. If you have enough metadata, you don’t really need content.” - NSA General Counsel Stewart Baker
That was an easy google search.
If you have something to hide from us, you are the enemy.
But most of us already knew this. So what I'm asking is:
* Are these well reasoned words affecting/effecting policy?
* How will we know?
I'm a huge supporter of universal end-to-end encryption, but Feinstein's point is making me feel some cognitive dissonance:
>"I think with a court order, with good justification, all of that can be prevented."
There are cases where I would want law enforcement to be able to read encrypted communications in an emergency situation, with a valid court order. If someone is being held hostage, for example. Of course I don't want intelligence agencies having this same access; just very specific requests during exigent circumstances, with judge approval. A real judge in a real court, not a secret FISA court.
But to do that you need some kind of key escrow already set up with the government, and if you have that, there's nothing stopping law enforcement and intelligent agencies from spying on what they want when they want.
Right now this isn't a huge problem since a lot of people still communicate in plaintext, or things that are encrypted but logged/intercepted by a central location (Skype). But eventually more and more things will move to end-to-end encryption.
What is the right way to handle this?
Remember that a police force doesn't need infinite, perfect access to all of a target's communications to catch them. Think about the case we're describing: we have enough information to convince a judge that this person is a suspect. In order to get evidence to convict, you can:
* hack into their devices to retrieve stored data or install malicious software like keyloggers * bug their place of living and work for video, audio, and WiFi capture * interview/interrogate them, and everyone they associate with * search their place of living and work * place tracking devices * watch their every move with drone or human surveillance * have a human or drone tail them * record all the metadata from their Internet communication * record the contents of any unencrypted communication
We actually have all the access we need, particularly since we're allowed to hack into the target's devices. The only thing we CAN'T do, is include the target in bulk communication capture schemes. We actually have to pick targets and spend resources on them.
To be honest, I might be OK with that practical limit even WITHOUT a warrant requirement. If a police force believes that a suspect is worth spending their limited resources on, they must be worth something. If adding someone to a watch list is free, they'll do it to everybody.
So you're happy getting rid of the Fifth Amendment then?
http://ottawacitizen.com/news/local-news/0407-password
As tools become better, is the price we pay for strong encryption that criminals who are mildly technical can get away with their crimes? That's hard to stomach if it's the 'right' answer..
But obviously, I don't want CP or terrorism subjects to evade detection and prosecution because of encrypted drives or communications.
Encryption can facilitate evil, but it also protects against evil. Universal adoption is hampered by obstacles including:
1. It's hard to do.
2. It's hard to understand, even if the tools become more user-friendly.
3. Most people will share a private key with a stranger when asked.
The right way to handle this is to encourage people to use strong encryption and acknowledge that it can be safe from eavesdropping, but still subject to weaknesses or participants revealing the information in other ways.
It could improve the effectiveness of law enforcement to force them to focus on meatspace crime rather than playing with their shiny computer toys.
Separate from the debate on whether this is a good idea, I'd love to see a proposal for how a global encryption ban could actually be implemented.