CA assembly member introduces encryption ban disguised as human trafficking bill
asmdc.org
asmdc.org
- Phones aren't going to replace credit cards - You will need to type in all your passwords each time you use them - Two Factor authentication will need to be done with a different device - Healthkit and other medical records will need to be moved elsewhere - Any profession where there are very serious consequences for leaked communication will no longer be able to do it through their smartphone (lawyers, doctors, executives.)
Basically losing or having your mobile phone stolen will be equal to a burglar pulling up to your house or office and driving away with every sensitive document and record in the back of a van.
No tech company wants to see the end of the mobile revolution. Forget the national interest side to this, anyone supporting broken encryption basically looks like a total moron.
Line 1
Line 2
becomes: <p>Line 1
Line 2</p>
which displays as: Line 1 Line 2
If you want to make bullet lists on HN, you have to have a blank line separating each item.Wrong Way:
* Item 1
* Item 2
* Item 3
(unless you're aiming for this: <p>* Item 1
* Item 2
* Item 3</p>
)Right Way:
* Item 1
* Item 2
* Item 3
HTML: <p>* Item 1</p>
<p>* Item 2</p>
<p>* Item 3</p>
Renders as:* Item 1
* Item 2
* Item 3
Some people use <pre> blocks (as I've been using above to show examples). This breaks on long lines, because there is no text wrapping (instead the element becomes horizontally scrollable). Like this:
dfjgkhsfdlgkjdfgkjfdhldskfjghdkslfjghdflkjshdfglskdjfhglsdkjfhglsdfkjghsdlfkgjhsdflgjkhsdflgkjshdflgjkhsdfglkj
afgkjhsdflgkjhdflgkjsdhfglskdjfhglsdfgksjdhfglsdjkfh
If you are editing your HN post in something like Vim or Emacs, you could wrap the text to N columns (something like 50 should probably be decent): - Lorem ipsum dolor sit amet, consectetur
adipiscing elit. Nulla at lorem id eros
tincidunt tempus. Fusce maximus efficitur
tempus. Suspendisse auctor sem ligula, quis
iaculis ante aliquam vel. Suspendisse potenti.
Integer magna arcu, consequat laoreet nunc
nec, pulvinar consequat justo. Cras sed velit
sed odio ultrices ullamcorper. Suspendisse
semper, urna ac vehicula vestibulum, mauris
urna euismod velit, ac gravida mi purus sit
amet mi. Sed commodo, turpis vel iaculis
rutrum, justo nisi venenatis lacus, et pretium
purus erat vel risus. Duis vulputate elit at
orci auctor facilisis. Donec eu urna congue
risus dapibus porta. Donec efficitur vel lorem
sit amet fermentum. Suspendisse potenti.
Aenean dictum, lorem non tristique commodo,
nulla urna rutrum odio, sed sodales enim nisi
eu tellus. Vivamus efficitur dictum est at
laoreet. Sed ornare nulla in ante tincidunt,
ac sagittis mi varius.
But you have to remember to "manually"[1] wrap the text yourself.[1] Manually in that something other than HN will have to wrap the text for you. You can either do it be hand, or put technology to work for you... just not HN technology.
If it did like HTML and completely ignored linebreaks as extraneous whitespace, that would at least be consistent; if it expanded single linebreaks to doubles, that would be enforcing a layout preference for inter-paragraph blank lines; but "ignore one linebreak, print two linebreaks normally" is just weird.
Hopefully there's a primary challenger or soon will be, I'll donate.
[1] https://en.wikipedia.org/wiki/Elk_Grove,_California#Top_empl...
[2] http://www.bizjournals.com/sacramento/news/2015/12/07/someth...
{note: [2] gives a significantly larger current headcount than [1]}
I think the proper political theory axis on which to hang this debate is libertarian-authoritarian, both of which exist in liberal and conservative thought.
And for what it's worth, I hope the Al Jazeera America cutbacks don't affect the excellent written journalism you all do.
Thinking of Silicon Valley as the both the bad guy and the good in the fight for privacy is quite interesting. On the one hand these big companies fight for anti-surveillance measures and they fight against laws for weakening encryption. On the other hand, they fight against laws designed to curb dissemination of private information and general consumer protection. This dichotomy is really striking to me.
http://arstechnica.com/tech-policy/2016/01/yet-another-bill-...
A few questions I posed to the NY senator earlier this week:
1. Would you use such a phone knowing that the government / apple / seller of the phone could easily get into it. 2. Would it be legal for someone in the legal profession to use such a phone without being disbarred for negligence of the right to private communication? 3. If sold unlocked, and then later locked (i.e. every phone right now), where's the change? 4. Where's the 4th amendment fit in with this? 5. What should we do with old phones that don't support this? Dump them in the bay I guess? 6. Where are the technical experts that are telling you that this is actually feasible to do securely and safely? I'm looking hard, but only seeing negative responses from those that know what their talking about. 7. Who's responsible for fixing the broken device once the master key gets leaked? The manufacturer? The state of {CA/NY}? 8. the list goes on.
"(d) (1) ...that is not capable of being decrypted and unlocked by its manufacturer or its operating system provider shall not result in liability to the seller or lessor if the inability of the manufacturer and operating system provider to decrypt and unlock the smartphone is the result of actions taken by a person or entity other than the manufacturer, the operating system provider, the seller, or the lessor and those actions were unauthorized by the manufacturer, the operating system provider, the seller, or the lessor."
Presumably the "those actions were unauthorized" could be construed as prohibiting a FDE option from being built into the OS and provided by the manufacturer and this in conjunction with signed kernels in phones, would present a very high barrier on the user to be able to obtain device encryption without key escrow as we understand it today.
A gun seller does not 'authorize' someone to use the gun to commit murder. Best buy, AT&T, etc. likewise do not authorize a user to encrypt their device. Nor should they. What I do with my device is none of their concern so long as I pay my bill.
Here's the CA bill: http://www.leginfo.ca.gov/pub/15-16/bill/asm/ab_1651-1700/ab...
Here's the NY bill: http://legislation.nysenate.gov/pdf/bills/2015/A8093
I'm going to make it clear to Jim that I'm going to give money to his political opponents in his next election.
https://en.wikipedia.org/wiki/American_Legislative_Exchange_...
It's a worrying trend, though. It seems every few months another law like this is proposed. Requires constant vigilance on our part.
"Please avoid introducing classic flamewar topics unless you have something genuinely new to say about them."
I've also seen guns and gun control discussed many times on HN without flames. So I'm not quite sure it qualifies as a "classic flamewar topic" on HN even if it qualifies as such among the general population. I would also argue that the GP did, in a sense, have something new to say about it.
Scaring people into giving up their rights is a tactic that's been used by both the right and the left for decades.
I think there's a general point that can be made about understanding restrictions in general and about when and why we should support them, but I don't know exactly what the general point is without resorting to a thing that most people write off as a meaningless platitude (e.g., "Those who sacrifice liberty for security deserve neither.")
I'm going to riff a little bit here, if that's okay.
I think it's worth asking--at each moment that any basic liberty that's even talked about in the constitution comes up for discussion, regardless of how you personally interpret that liberty--who benefits from a reduction in that liberty?
It's perhaps easy to say, for some people, that reducing the number of firearms in circulation is a net benefit for "the people" as a whole.
But I don't think that's a correct answer to the context of my question above. If you view the constitution as a social contract between the citizens and the government, reducing freedoms of any kind is always to the advantage of the government and always to the disadvantage of the people, even if in the short run fewer people die from firearms-related deaths.
Similarly, I would suggest that in terms of privacy, there are people who are willing to sacrifice their own privacy (as well as mine) by outlawing certain encrypted devices because they think that will make us all safer from--something? Are we going to define certain phones and tablets and computers as Assault Devices and make them illegal if they have a pretty fruit logo? Or run an OS named after a cute robot?
The problem is that our government is made up of people. People who are trained just exactly the same ways that we are: by positive and negative responses to actions. People who learn by experience that doing a thing that makes their lives easier (removing freedoms) can be accomplished by stigmatizing the exercise of that freedom.
Voila. There you have all the explanation of why freedoms are in a constant fight against being reduced. It's not because of any conspiracy or because governments are bad by default, or anything nutbaggy like that. It's because the basic approach of human nature is to make your life a little easier. That's it.
Reducing freedoms make the lives of the people in government agencies easier. That's all there is to it.
My opinion comes from some odd experiences in my life. I'm from Texas, but I live in NYC. I like guns, but I also support abortion rights. I was trained as a classical violinist but write code for a living. I studied Aristotelian philosophy and categorical, deductive logic; I work on data with inductive methods.
I think that a lot of the disagreement between parties is manufactured, that people who care deeply about liberty in whatever form it takes: guns, abortions, free speech, privacy . . . whatever--people who care about these things have a lot more in common than they often realize.
I wish there was a better way for us to work together and understand that all freedoms live or die based on our group commitment to all freedoms, not just one or two that we happen to feel good about right now.
Hanlon's Razor is usually a good idea, but it should only be used when all else is equal. That is not the case here, as we know there are long-term (since the first crypto wars) attempts to restrict encryption.
Whoever wrote this bill has a very good understanding of the subject matter. What you call "incoherent" is a feature in the eyes of anyone trying to restrict crypto. Poorly-specified laws provide room to selectively enforce the law or reinterpret what it means.
I wish I had a dollar for every case I've reviewed where a judge had to interpret a poorly written(bad or ambiguous grammar) statute. Many of the judges got it wrong, probably intentionally in a few instances, and the decisions were later overturned, sometimes after the defendant had spent years in prison. And that's just the ones with happy endings.
For other actors in government, such as assembly members, full-disk encrypted operating systems increase freedoms - increase the freedom of having any political view while partaking in taboo activities, without their devices were monitored, without the threat of being blackmailed.
Truman stated that "we want no Gestapo or secret police. The FBI is tending in that direction. They are dabbling in sex-life scandals and plain blackmail.[1]
NSA won't say whether it spies on Congress.[2]
[1] https://en.wikipedia.org/wiki/J._Edgar_Hoover
[2] http://www.theatlantic.com/politics/archive/2014/01/the-dang...
To be clear, I'm against the inclusion of backdoors/side-channels/key escrows for anyone on the basis that it threatens the security of everyone for the chance that law enforcement might glean something off a phone. But I do think its important to be realistic and acknowledge that there are situations in which encryption impedes the usual investigative process for law enforcement, and that many time sensitive cases may result in serious harm to individuals as a result.
I do believe that most people calling for backdoors do so in bad faith, but it's not difficult to imagine actual scenarios in which such complaints do impede an investigation. Coy reductio ad absurdum statements really don't help the discussion at large along in either direction.
For reference, the ability to do this hinges on the Definition of "Sold in California" which is defined in -uh- CA Code 22761.(a).4 which reads:
'(4) "Sold in California," or any variation thereof, means that the smartphone is sold at retail from a location within the state, or the smartphone is sold and shipped to an end-use consumer at an address within the state. "Sold in California" does not include a smartphone that is resold in the state on the secondhand market or that is consigned and held as collateral on a loan.' [0]
[0] http://www.leginfo.ca.gov/cgi-bin/displaycode?section=bpc&gr...
Also interesting, the language only says "smartphones" so this doesn't include devices that aren't smartphones. OK tablets and laptops aren't included then. But what is a smartphone? What about an iPod Touch? Only if the device has a GSM/LTE/CDMA radio in it is a smartphone?
"Smartphone" has the same meaning as in Section 22761.
http://www.leginfo.ca.gov/cgi-bin/displaycode?section=bpc&gr... 22761. (a) For purposes of this section, the following terms have
the following meanings:
(1) (A) "Smartphone" means a cellular radio telephone or other
mobile voice communications handset device that includes all of the
following features:
(i) Utilizes a mobile operating system.
(ii) Possesses the capability to utilize mobile software
applications, access and browse the Internet, utilize text messaging,
utilize digital voice service, and send and receive email.
(iii) Has wireless network connectivity.
(iv) Is capable of operating on a long-term evolution network or
successor wireless data network communication standards.
(B) A "smartphone" does not include a radio cellular telephone
commonly referred to as a "feature" or "messaging" telephone, a
laptop, a tablet device, or a device that only has electronic reading
capability.
It seems like a tablet with a cellular radio could arguably fit that definition as well.It also, weirdly, suggests not anything 3.5G or lower. What? Why?
And in any case, Apple's end-to-end encrypted iMessage does not depend at all on such a cell network of any version. It does work on WiFi only just fine. So why are these devices exempt from terrorists and kiddie porn sickos and human traffickers?
If you're going to be serious about catching that, it seems like everything that does full disk encryption would be broadly included. Desktop and laptop computers, and tablets. Why does Layer 1 matter to this?
Maybe, but I think maybe not...
My 3G Nexus S "[i]s capable of operating on a long-term evolution network or successor wireless data network communication standards". This is because 3G LTE networks seem to also communicate with 3G, 2G, and 1G radios just fine.
Strongly disagree, because:
> (1) (A) "Smartphone" means a cellular radio telephone or other mobile voice communications handset device...
and additionally:
> B) A "smartphone" does not include a radio cellular telephone commonly referred to as a "feature" or "messaging" telephone, a laptop, a tablet device, ...
Not only are tablets specifically excluded in the definition, "mobile voice communications handset device" would likely exclude them from the definition all by itself.
To my knowledge the idea has not taken hold as the ham radio hobby moves slowly and the need for strong authentication is not typically a felt need of most operators who want to chat broadly and make new friends. It's part of the ham radio culture as a hobby.
"If You’re Typing the Letters A-E-S Into Your Code You’re Doing Wrong"
When the legislature wants to do something unpopular (or even stupid which is what this is), associate it with the "Evil Of The Era" and propose the bad legislation as the solution to said evil. These days, popular "Evils" are Human Trafficking, Child Porn, and "Terrorism". The first two evoke extreme emotion of crimes committed against the most innocent of victims, so they're the best choice in this scenario. In the 80s-90s it was anything to reduce "Crack Babies" or win "The War on Drugs".
It's an old trick -- when people talk about logical limits placed on the first amendment, you'll hear the phrase "Shouting Fire in a Crowded Theater". Most of those who utter it don't realize that this phrase originated as part of a ruling that had nothing to do with "fire" or a "crowded theater" but was made to curtail the dangerous speech of opposing the draft during World War I[1].
[1] https://en.wikipedia.org/wiki/Shouting_fire_in_a_crowded_the...
It doesn't say how, and it doesn't give a time frame.
So: Provide an API to accept a key. Allow two key attempts per second. Start with key 0x0000..000, next try 0x000..0001. This is guaranteed to complete, you just have to be prepared to wait a while.
(Yes, I know that courts are unhappy with this kind of thing. But the bill is a crappy bill, in many regards).
Lavabit found in contempt for trolling the FBI with 4-point font http://www.dailydot.com/crime/ladar-levison-lavabit-founder-...
The tactic suggested by the GP is similar, but distinct, and has a better chance of working because it isn't an attempt to circumvent the court itself. It's an attempt to have the law seen as vague and therefore void. Still, IMO, not likely to work, but it's not exactly like the Lavabit case.
These two bills are actually clever probes, IMHO.
What are the chances they run afoul of interstate commerce provisions?
But hey, C compilers are tiny. It's no problem to put one on a phone.
I would:
- Comply. Rip encryption out of the OS. [keep reading!]
- Make a plug-in for the crypto. That probably already exists in the form of a library, but in any event it doesn't seem hard.
- Have a system update -- one that is fetched very, very early in system setup -- download and install that plugin. To avoid the possibility that downloads can be blocked, you release the source code and give existing phones, already in many hands, the ability to compile that code on the device (some handwaving here, but you can probably make that secure, for specifically that plugin, and maybe exactly that version of the source). You need a way to distribute bug fixes, but again you're dealing with source that's not part of the OS.
That source-level plugin isn't an operating system, and we're back in territory where the government has to ban specific software components, and maybe ban source code (which is going to be a really difficult 1st Amendment argument).
Do you want crypto to work? Or do you want to be forced to replace crypto with security theater? Is your business actually willing to actively protect a free internet? Or is it easier to assume this is "someone else's problem"?
I guess we will see which companies defend themselves, and which companies think being a collaborator is more profitable?
Shall is the source of more litigation than any other single word in the English language. It can always be debated because no one knows if it reliably means "can", "must", "may", "might", "will", "should", "ought to", or "is allowed to".
All the above uses can be supported with evidence. Because language evolves.
It's killer word for any law or contract and guaranteed to be disputed.
I am not a lawyer, btw.
But if this somehow passes, it will get tossed because of the wording.
Shall means "will" or "must". Like any uncommon word I'm sure it's frequently used incorrectly, and I recognize that language evolves, but I have difficulty believing those other uses have become prevalent enough to be considered valid.
Do we start referring to encrypted devices without back doors as contraband?
As a matter of fact, I'm certain that current leaders of the EU countries who publicly invited immigrants to their state (we all know the most prominent one), was considering this as a easy way to change the privacy laws - and be applauded for it.