New York Wants to Force Vendors to Decrypt Users’ Phones
onthewire.io
onthewire.io
Would that be a bad thing?, so you are implying that encryption is wanted to actually hide crimes or unloyal behavior mostly?
OK, and why would that be a bad thing? if it is done in the context of a case investigation.
#2) in many jurisdictions a person who flirts with a consenting adult over text hasn't actually committed any crime in doing so
Which leads to...
#3) what is the point of decrypting said personal communications except to vindicate the estranged party's already fully-formed assumption that their spouse is a wicked person, or to exact some kind of court-sanctioned revenge.
I swear, sometimes in threads like this it's hard to tell if someone is trolling or legitimately can't ponder the unintended (or, perhaps, fully intended but thinly veiled) consequences of laws that serve to grant the state access to private communications.
The post you're answering to basically asks why removing privacy from society is a bad thing. I think that a simple link such as [1] is enough as an answer to this fairly common question, troll or not.
[1]: https://papers.ssrn.com/sol3/papers.cfm?abstract_id=998565 ('I've Got Nothing to Hide' and Other Misunderstandings of Privacy)
And why are getting angry? do you feel unfortable that my concerts my be legit?
Edit: You keep using the word "case". I do not think it means what you think it means.
w/o a proper answer, all I get is "Is not a case" and if I ask wht if there is case? I get people like you, so, do you have answer to the next question?:
What if there is case? why is it bad to use decryption there?
In my opinion it is important for society to maintain the privacy that humans have experienced for thousands of years. Remember that mass surveillance of every conversation that you have ever had is new thing. Before the internet society had much more privacy. Encryption is a way to ensure privacy in the internet era.
1) Because (in the US) of the fifth amendment, as I had mentioned before and you, it seems, either missed or chose to ignore.
2) Decrypting the device would, due to forensic procedures, result first in an image being taken of the entire device, meaning that content outside the scope of any discovery process or search warrant would then become available to the judge/state/prosecutor/government, and said content, depending on specific judicial rules in effect, may also end up as a matter of public record. It also means that anything you've said on your device's record, no matter how relevant, can be held against you without your ability to exercise your rights to refrain from speaking.
Privacy isn't about keeping secrets, it's about controlling access to the truth and ensuring that you are able to take an active role in any action that results in the truth being disclosed to a party who has the authority to take said actions against you.
Similarly, the fifth amendment isn't designed to protect criminals from confessing a crime which they in fact committed, but to protect an innocent person's "truth" from being taken out of context and used to bias a judge or jury against them.
Honestly, the more I think about it, it does boil directly down to freedom from self-incrimination (e.g. saying something that would get you in trouble regardless of its applicability or truth). Leaders in our history had the presence of mind to recognize that an authority figure could easily choose to punish anything said by someone who was, according to procedure, supposed to be innocent.
It's a moot point (encryption) in civil issues anyway. A civil complaint should not allow any random person to use the power of the courts as a bully to force their enemies to disclose their private information. There's a reason civil and criminal procedure are so different.
I'm taking your speech and applying my own context to it. Precisely what would happen to someone whose private communications are laid bare in a court of law, or indeed, to anyone.
Or, as the saying goes, "it doesn't matter where you get your appetite as long as you eat at home." If the racy conversations are a result of unhappiness in a relationship, it's a symptom and not a cause. If it were medicine, we'd aim to treat the cause in order to mitigate the symptoms, not punish the symptoms by making the patient parade them for the world to see.
In witch judiriction infidelity is no motive for divorce, I don't know any, and if that is the case? what about those judirictions where it is? why is a bad thing using decryption there?
Friend, if you suspect someone has cheated on you, HN isn't the place to go for validation. Talk to your partner.
meanwhile terrorists just roll their own encryption software, making regular citizens less secure than them.
http://www.defenseone.com/technology/2016/01/isis-now-has-ne...
Their texts will look like:
- my girl is not with me, I left her at discowild
- nothing happened mate, no idea why?
- relax fam, ask mike to present you another girl, he is partyng next to dominoes. We getting wasted today tho, no bs
And now is completely impossible to differentiate that conversation from all the other 10 billions texts that happen at any Saturday night.
This is extremely obviously a power grab at controlling normal, law-abiding citizens. "Terrorists" are the new "paedophiles" - a sad excuse to remove the privacy and rights of ordinary citizens while being able to ask whether you support terrorism (or paedophiles) if you stand against it.
[0] https://theintercept.com/2015/11/18/signs-point-to-unencrypt...
But is seems like these issues have passed muster before. Consider that California has stricter environmental regulations concerning the cars that are sold there than many other states. The manufacturers simply make cars that meet the California standard and sell them pretty much everywhere (at least I'm pretty sure that use the be the case, haven't kept up with it though).
If that local regulation has passed any and all legal tests, then I would be surprised if New York couldn't act independently in this case. And I think the manufacturers would simply do something similar: you'd end up with compromised security on all devices that come under the law even in states where that law didn't exist.
Many manufacturers still distinguish cars with "California emissions".
But I don't go out of my way to do such. With the emissions argument, lower emissions is generally accepted as a positive feature, though some may dislike the reduced performance or increased cost associated with it in some instances.
Backdoored encryption is not something generally accepted as a positive feature, and I suspect many people will specifically seek out non-backdoored devices if the law is passed and manufacturers start making devices for the lowest common denominator.
But since this is a software feature, I see no reason why a single device couldn't serve both markets, with a fused bit somewhere permanently enabling the backdoor.
But, as said previously ad nauseam, the law would stop criminals about as effectively as the anti-radar detector laws keeps radar detectors out of Virginia.
The widespread use of instant-on radar and LIDAR has done far more to curb the widespread use of them, in all states, by simply making them ineffective.
Seems most of the current law applies to them as electronic communications, but I think they are becoming more and more like a safe deposit box, which I think has fared a bit better. It's unfortunate that it will likely take a few guinea pigs with a lot of money and the right type of case to force the judicial system to work this out.
Of course, the prudent criminal would encrypt anything, using non-backdoored encryption, before it left his/her control thus making LEO/Government access to their cloud storage ineffective.
This is what China wants, so if Apple isn't going to stop selling in China on principled grounds, then why would they stop selling in NY or anywhere else that decides to go down this path?
As for enforcement, every state has its own rules for merchants. NY State has the business license and if you don't follow their laws they can withdraw the license and now the company can't sell product in the state.
The thing that irks me is this transparently targets average Joe User and below average crook. Because only those two groups will end up with either weaker encryption (breakable encryption, including backdoors) or keys being escrowed. Anyone who understands this, including the above average crook and far worse, will just get some other product that uses escrow-free strong encryption that isn't subject to that state or that country's laws.
The idea is, governments would never cease their attempts just because there are some objections and counterpoints. But after a grand fuck-up they won't dare to try it - and if they do they'll be told "you want another New York, eh?" and that will work.
It has a good chance of happening in one of those markets if not here and then, it's just a matter of time till many nations demand the same.
I don't have any data on China and India. They might be more lucrative markets due to the size.
That being said, the number of old ladies I see on the metro with iPhone 6's makes me somewhat envious.
[1] - http://www.re-store.ru
The cops will backdoor the phone and decrypt it, only to find a file called "my-awesome-terrorist-plot.doc.aes".
I think only an effortful, informed, and motivated individual would buy their phone out-of-state. Plus, I'm pretty sure NY won't be the only place enacting such anti-encryption measures.
Eventually, those who advocate for encryption and privacy will be out of the moral mainstream, and will have a tough PR road ahead of them.
Presumably assemblyman Titone knows this, and is expecting the bill to do nothing other than provide the usual security theatre. That, or he is dumb as a post. Could go either way :-)
I expect to see congressional level legislation like this very soon. That'll be significantly more interesting.
Customers need not experience inconvenience if this is done right.
There are obvious reasons why the police would actually want this beyond security theater (PR). It actually makes their job easier.
I'm sure companies and politicians know very well that while you might not be able to organize a get-out-to-vote drive for privacy, you can do so for inconvenience. Compliancy with multiple devices is easy and already done.
> Most people just buy their phones without thinking,
> and would find this encryption debate a little
> technical. They probably also think that they won't
> be personally inconvenienced
I don't believe this. Everyone understands they have secrets (affairs, medical conditions, getting high on the side, their xvideos search history). Getting the messaging right is not so hard.Take the UK "Draft Communications Data Bill". Once it had attracted the nickname "The Snoopers Charter", and you get the gutter press talking about how meddling officials in the local councils will use it check up on if you've been researching council tax banding, public opinion can be made to turn against it very very quickly. The replacement bill they're currently debating is far from perfect, but a lot lot better.
It's our duty, who do understand the technical aspects, to bring them to life for our friends and family. I've mentioned it before, but images like this[0] presented the exceptionally dull topic of net neutrality in a way that normal internet users cared about.
Extrapolate what this will mean in practice, and make stories from it. You get pulled over on a traffic stop, and a cop decides to copy the data off your phone, and finds your messages about buying your 20-year-old son beer. You lose your phone, it gets handed in to the police, and some jobsworthy sergeant decides to flick through, and find saucy photos of your ex-gf and sends them to his buddies. People may not understand encryption, but everyone understands privacy.
[0] http://images.huffingtonpost.com/2010-12-15-net_neutrality_l...
You vote against that bill and your opponents are going to mention that you obstructed the funding of the armed forces -- and you did. It's just that there was nuance to the event, nuance that always gets lost when the varying disseminators of information go out to organize votes.
That's because you haven't stopped the factors behind the bill. There's a natural bureaucratic motive to being able to control citizens. There are police unions lobbying for this kind of stuff, unions who will make note that you voted against their favor.
Reddit got tired of SOPA and CISPA-esque stuff. They probably couldn't convert the PR injury into actual votes that mattered in the states that matter, so it's just noise anyway.
The main opposition to kill switches came from phone carriers because they make a lot of money selling (1) replacement phones to people whose phones are stolen and (2) theft insurance to people who fear their phones will be stolen, and from some privacy and civil rights groups that (1) misunderstood the bill due to not reading it carefully and/or (2) were basing their opposition on completely ridiculous scenarios [1].
[1] For example, some claimed that police could use the kill switches to quickly and without a warrant shut down all the phones of protestors to stop them from reporting and filming police brutality. That was a ridiculous scenario for several reasons.
First, the kill switch involves sending a targeted command to each specific phone to be killed, so the police would first have to bring in something to identify all the protestor phones. Then they would have to go to the phone maker or the carrier (which depends on how the particular kill switch works for that phone) and get them to send the command. There is no particular reason to believe that the companies would have a procedure for that, so this could be very slow...and there is also no reason to believe it is even possible, because nothing in the law requires that the company can kill the phone without the cooperation of the owner.
By the time they do all this, the protest is likely to be long over.
Furthermore, the law only applies to smartphones. People with feature phones would be free to report and record unfettered, as would people using tablets.
On top of that, the law allows (and as far as I know every implementation implements) the phone owner to turn off kill switch capability, so the "use the kill switch to cover up police brutality" plan only works if none of the protestors are smart enough to turn off the kill switch before joining the protest.
If the police actually, in the real world, were going to try to block protestors from reporting and recording with their phones they would do it by trying to get the cell towers in the area shut down, or by using Stingray-like devices in active mode to intercept and block communications.
This is where you go off the rails. There's little reason to believe that the companies would have a procedure for doing this for the first time, there's a little more reason to believe that they would have a procedure for doing this the second and third times, by the sixth and seventh times they want do do this, it will be surprising that they don't have a procedure, and by the tenth and eleventh times it will be negligent that after all this time, they haven't managed to put a procedure into place.
By the 30th or 40th time, there will be a police issued Android app to send in GPS coordinates and request a radius, and at headquarters, someone will type that into an app running on Windows XP and then click "OK."
And they won't install any apps or use any other means to hide their illegal goods/communications.
Just like the ones with violent felonies/intending to commit violent felonies will only lawfully acquire guns to commit violent felonies.
Can someone explain please what I'm not seeing? I give you our politicians are sometimes not the smartest, but it doesn't take even an average IQ to see the logical failure here. That being the case, these elected officials must know that this won't solve the problem.
So what is their ulterior motive in spending so much time chasing after a law that will do very little to stop real crime? Just so they can look like they're doing 'something?'
Cell dealers in the state would simply not have any phones to sell that comply with the law, and New Yorkers would either go without phones or would buy them from out of state on eBay. I'll let you guess which of those outcomes is most likely. Apple Stores in New York would have to stop carrying the iPhone. Of course none of this will ever happen, because this bill is idiotic and would cause enormous economic damage to the state. But dangerous, ignorant politicians like this should be voted out of office at the earliest opportunity.
The endemic corruption and routine prosecution of NY legislators gives me hope that this thing will go nowhere, because they have something to hide.
The bill is more of a trial balloon.
In the past, if you wanted a decent life, you kinda had to live in a big city. Now, however, thanks to the Internet, that is perhaps becoming less the case? The Internet now has a fantastic selection of shops. You'll also find lots of radio stations, music and video streaming online. There are more and more opportunities for remote work.
On the other hand, a city of 10 million has far more restaurants, clubs and social opportunities than a city of 1 million. So I'm not really sure whether big cities are becoming obsolete. Still, I'll be reluctant to move to a big city if it means that I have to give up my privacy. Not saying I'll never make such a move, but the balance of pros and cons seems to be changing.
* It is possible to ensure that encryption will physically destroy the phone. Preferably it destroys the antenna, the screen, the battery, etc. In that case the law must be pretty sure, you're the bad guy and the use of it as a backdoor becomes limited to people that value your data above the value of your phone.
* If manufacturers have to open up parts of the phone to certain parties, there is a possibility that they have to open up these parts to the consumer as well. It might have on the long term a positive effect on the ability to root your own phone. If the government might own my phone, perhaps I might myself own my phone as well.
Just my two cents!
Pretty sure me and some random mugger are the only people who even care about the value of my phone.
>there is a possibility that they have to open up these parts to the consumer as well.
There is a whole lot of precedent that says this isn't going to happen. Even if manufacturers wanted to do this, I'd expect we'd see laws in turn which gag them so that " the terrorists can't break our backdoors".
The reality is that these statehouse bills are normally trumped (I hate that word now) by federal legislation. Even if not, there are enough people in places like NY that understand that the courts will shred these things. So they never pass. Once the news is over, once the bill proponents have made their peaches, they are quietly disappeared.
Note: I'm not endorsing this, but I do believe it would satisfy the governments.
So far this is "data at rest" request. It's for data on the phone. It's not for data in motion which is another technology that PFS makes rather difficult to impractical to setup key escrowing for, that's sorta the point. But then, the basebands are all proprietary and probably compromised by state (nations) actors.
"The fact is that, although the new software may enhance privacy for some users, it severely hampers law enforcement’s ability to aid victims."
This is actually an argument against privacy itself. Astounding.
Andrews & Arnold is pretty much the only uncensored ISP in the uk.
Pretty smart in retrospect to force the government to play Bad Cop.
See also:
https://theintercept.com/2016/01/12/apples-tim-cook-lashes-o...
You will get vastly different answers depending on which phrasing you use. That's what the politicians count on.
It would be interesting seeing how this would play out with an individual state though. Would Apple make a special NY version and advertise loudly that it's defective by design, or would they kowtow to a backwards state government to avoid a legal showdown?