Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate
cyber.law.harvard.edu
cyber.law.harvard.edu
https://www.lawfareblog.com/out-box-approach-going-dark-prob...
Those people on the sides that do care then shape the debate and ultimately the outcome of pretty much any democratic decision (as little as those are still left).
They want the path of least resistance, which isn‘t good for security or privacy.
So the link to this military contractor's death to ISIS is very tenuous. This has to be established first, and there is almost nothing to establish it on - he was a Jordanian police officer, not an ISIS militant. Then you have to say Twitter is engaged in running afoul of material support of terrorism laws. These laws generally would mean something along the lines of that in some back office of Twitter, Jack Dorsey was storing up Kalashnikov rifles which he was going to ship to the Taliban in order to assault American bases there.
In 1929, the Republican (!) Secretary of State rolled up all the old World War I spying operations saying "Gentlemen do not read each other's mail". How far the US has fallen in freedom from the day Stimson uttered those words a century ago.
He also turned it all back on, to 11, as the secretary of war, once stuff heated up in Europe.
Thus, the government has always had a way to search the long-distance communications mechanisms of its day. Wiretapping telegraph or telephone lines was not deemed a violation of the 4th amendment until 1967. Even after that, a wiretap was authorized with a warrant.
Now, you have a pervasive mechanism of long-distance communications, and it's increasingly opaque to the government, even with a warrant. That's an unprecedented state of affairs.
The two differences now: we've made that technology available to non-experts, and we hope that no amount of government effort can crack the scheme (as opposed to obtaining the key).
I agree with your comment that it's not a "fake crisis", though. It's one with only one right answer, but it's a "crisis" in the sense that no possible path forward will make both parties happy, so we fundamentally need the government to either realize they're wrong or to lose. Government positions don't change easily, and governments do not like to lose.
While it bothers me to see terms like "common ground" used, as they imply that both positions have grounds worth considering, I do think one of the few paths that has a hope of success is to convince the government that there exists a position they can adopt that doesn't look like it goes back on their current stance.
> It's one with only one right answer, but it's a "crisis" in the sense that no possible path forward will make both parties happy, so we fundamentally need the government to either realize they're wrong or to lose. Government positions don't change easily, and governments do not like to lose.
It's not the "government" versus "the people." It's a small group of people who strongly support surveillance, a small group who strongly oppose it, and a mushy middle that tends to lean towards whatever makes them feel safe. People in each group are represented within government, though for obvious reason people in the first group tend to gravitate toward positions involving national security or defense.
You're calling them products but the relevant thing they want to regulate is still more speech.
If you want to communicate with your friends in code then you first have to communicate the code itself. In this context the code is code, but code is speech.
[1] Bricks can also be expression in unique contexts. That doesn't mean that bricks are speech.
It happens we have machines that will turn that information into action, but the code isn't the machine or the action. It's just a type of speech that machines can understand too.
People are always wanting to regulate speech by combining it with a machine, but the machine and the speech are separate. They don't have any specific relationship. Apple makes a) a general purpose computer and b) computer software. But (modulo DRM/copyright) you could run that software on any general purpose computer and use that general purpose computer to run any software.
It's like trying to regulate what information you can print in a newspaper by claiming you're regulating the printing press.
It is speech. If you wanted to you could even go find the source code and translate it into english in such a way that a relatively competent programmer could turn it back into code ("If the first bit in the byte is 1 then do .... other wise do ....").
But it's clearly also a tool. I've never read the source code to the software I use to encrypt my hard drive. It's unlikely that I ever will. I just care that it does the job I want it to.
Trying to say that it's either one or the other is silly. It's both.
But just because it's speech doesn't mean that the government might not have an interest in regulating it. The first amendment is not absolute. I can imagine a great many prima facie arguments supporting the idea of regulating encryption software. The fact that code is speech is not, in and of itself, a defense against any of them.
As with most cases of constitutional law, it comes down to weighing competing interests. Failing to acknowledge these varying interests fails to acknowledge the actual question at hand.
I'm not trying to say that it's one or the other. I'm trying to say that there is no part of it that isn't speech. There is not a part which is a tool and a distinct part which is speech. The whole of it is speech. All you're saying is that it's possible to use pure speech as a tool. But what of it?
You can't win by talking about balancing because encryption software is meta. You can use it to distribute it. If people who are breaking no law have the right to be able to communicate without government surveillance then the government would have to violate that right universally to enforce any rule restricting the distribution of software, because distributing software over a secure channel is indistinguishable from any other communication of the same size. It's hard to imagine anything that could justify that level of intrusion, and certainly not anything that has been proposed as a countervailing interest in this context.
As to your printing press hypothetical, I don't think it applies. Say the back door is something like "must keep the decryption key around in case a warrant comes in." That doesn't entail any modification to the "speech" coming out of the device, does it? So how does it restrict speech?
Maybe it helps to better define what you mean as the product whose operation is to be regulated. If it's the hardware, it's a general purpose computer that can run any software. We quickly go to a bad place if you can't buy such a thing, e.g. side-loading on Android is prohibited, Raspberry Pi and RISC-V are prohibited, every device must prevent you from compiling a custom program and running it, etc.
But if it's the software then you're banning the publication of encryption code.
Obviously the confusion stems from Apple being the go-to example and Apple not only providing both the hardware and the software but also actually enforcing the kind of restrictions on what software the user can run that would be unreasonable as a requirement imposed by the government on the entire market. Apple could [try to] prevent you from using encryption software on an iPhone, but it makes little sense to require only them to do that if anyone can still run it on an Android phone or PC. But the alternative is that nobody can buy anything capable of running Debian or OpenBSD (or even Windows).
Moreover, the operation of the product is the thing carried out by the owner, not the manufacturer. Apple makes a nice machine and a big detailed list of things you can do with it but the user is the one choosing which buttons to press.
> As to your printing press hypothetical, I don't think it applies. Say the back door is something like "must keep the decryption key around in case a warrant comes in." That doesn't entail any modification to the "speech" coming out of the device, does it? So how does it restrict speech?
So there are two questions here: One is, can I have the code that doesn't keep the encryption key? If not then it restricts the speech you can receive and that of other people who want to give you that code (perhaps so you can use it to communicate more sensitive information with them).
Then there is the key itself. Keeping the key (or sending it to Apple or Uncle Sam) is compelling speech. The key is also information and the key + ciphertext is equivalent to the plaintext. It's equivalent to a requirement that you keep the plaintext of all your communications.
It would effectively be compelled written testimony before the fact. Either you keep everything written down or go to jail for not having it.
> It would effectively be compelled written testimony before the fact. Either you keep everything written down or go to jail for not having it.
While I agree with you, that particular argument won't necessarily succeed, considering https://en.wikipedia.org/wiki/Sarbanes%E2%80%93Oxley_Act and similar laws regarding reporting and information retention policies. You don't want the government equating policies to protect user communication as equivalent to destruction of evidence.
I am pretty...unsympathetic...to this interpretation.
Not because you have to but because you can. It proves the "tool" is pure information. Speech.
Banning effective encryption, or banning commercial encryption, is still effectively banning encryption, or forcing it underground and casting suspicion on it.
> It's not the "government" versus "the people." It's a small group of people who strongly support surveillance, a small group who strongly oppose it, and a mushy middle that tends to lean towards whatever makes them feel safe. People in each group are represented within government, though for obvious reason people in the first group tend to gravitate toward positions involving national security or defense.
The people within government who oppose backdoors have yet to be very vocal, or effective. I'd certainly love to see a large outpouring of support from government, to counter the level of support for the pro-backdoor position.
Many people in the tech community don't want to get behind those in government who oppose back doors because they are not absolutist in their rhetoric about privacy. They want to assert there there is not even a debate to be had between security and privacy and that privacy should always win. But when the vast majority of the actual voting public is concerned just as much about safety as about privacy, if not more, that's not a tenable position for elected and appointed officials to take.
The comments by the NSA director didn't seem to have any significant effect on the general government message. As for the White House position (which I had not seen the announcement of, so thank you for the link), they said they won't seek legislation, but they hardly need to at this point; those in Congress seem more than happy to keep proposing such legislation, and I've seen no suggestions that the White House would veto it if passed.
http://vjolt.net/vol2/issue/vol2_art2.html
As Eben Moglen also observed in a closely related context, Americans have also always had the right to use languages or shorthands of their choice when communicating, many of which significantly (perhaps even entirely) hindered the government from understanding them, and sometimes by design.
This isn't a unique case. Sovereign power is potent, but it isn't unlimited in theory or practice, and it isn't unchanging. Genetic modification, cheap aviation, robots, 3d printing, cryptocurrencies, etc. challenge sovereign power and related stakeholders. For good and ill.
It is doubtful that genetic engineering can be meaningfully regulated. That's probably got consequences greater that perfect secret-keeping. Governments will have to get over it.
The reason you don't hear about that as much is that authoritarians and control freaks don't obsess on it. Or don't know that maybe they should, because you can encode a lot of information in dna and smuggle it inside a tiny insect.
That would be mildly interesting - if this were a 4th amendment issue. It's not.
It is a first amendment issue. If I choose to communicate with you with a (seemingly) random stream of numbers, that is protected by the 1A of the Bill of Rights. Just like a KKK rally.[1] Just like burning a cross.[2] Just like Piss Christ.[3]
[1] https://en.wikipedia.org/wiki/Brandenburg_v._Ohio
Further reading:
[1] http://www.independent.org/newsroom/article.asp?id=478
[2] http://law.stackexchange.com/questions/3696/is-the-right-to-...
Today many analogous conversations take place online, in instant messages, in email, and in other persistent media. Even when the content of a communication isn't recorded as an artifact of its medium of expression and transmission, there's almost always a record left behind to indicate that the communication took place, revealing associations and hinting at what was said.
So by emphasizing the legal history of searches of "long-distance communications", you've moved the goalposts by a mile. Changes in the way we communicate with one another, reflecting changes in communications technology (and changes in society), mean that governmental powers in searches and surveillance, powers which formerly applied only to relatively rare forms of communication, now apply very broadly. At the same time the government's cost of performing such searches and surveillance has plummeted, multiplying the power of police and spies to monitor our words and use them against us.
It's an unprecedented state of affairs, indeed.
And maybe in such a way that creates the worst of both worlds. The sufficiently informed and conscientious covert actor can find some way to keep much of their communications obscured. This utterly freaks out state apparatuses that consider legibility a key goal. So they work harder to more broadly collect signals AND chip away at obscuring methods. Would-be coverts escalate. So does the state.
End result? It could well be that the motivated/educated still can keep enough of their secrets hidden, but communications for the mass of people who don't have the reasons/resources for participating in the arms race end up largely transparent. And, well, if the resulting panopticon falls short of realizing its original purpose, it's still bound to have a certain amount of utility one way or another -- at least, not without a high degree of accountability.
In the age of the internet, that protection has been lost, and the government has taken advantage of the increased ease of surveillance to try to monitor everyone, all the time. Unfortunately, there's no way to put the genie back in the bottle--we either put up with ubiquitous surveillance, or fight it; either way, the era of limited, focused surveillance is over.
95% of cases are made via informants and not CSI-type investigations, so the whole "going dark" thing, I feel, isn't going to affect law enforcement the way a lot of people think it might.
I did notice, however, my last time through the system last year, that the State is now making a bunch of cases using cell tower information to put the defendants near the crime scene during the approx time of the situation.
Just FYI.
And I'm not at all happy with the implications of what "they" want...
I think this will reduce their ability to target people for political reasons.
It seems to me that all this report is saying is: "Hey government, don't worry about tech 'going dark', we will still have the ability to spy on people through their poorly implemented Internet of Things devices, services that won't use end to end encryption, metadata, and because software is still fragmented."
But they don't seem to even slightly condemn the simple fact that governments are turning into surveillance machines...
For unbreakable encryption, I'd suggest XORing with the contents of /dev/random (assuming /dev/random is unknowable). Of course decryption may be an issue.
If you're doing two rounds, it's even easier!
Also, why is this framed as "going dark"? That's the ignorant people's wording. Why doesn't the author call it what it is: key escrow, or back-dooring? Use the terms of the industry you are talking about.
The Surge and the War On Terror were branded by their supporters. Obamacare was branded that way by those trying to defeat it, but it hasn't worked. So, not sure your examples illustrate your point.
For example, the US supports Chinese dissidents, and maybe Thai dissidents, but for sure not ISIS. And so decrypted ISIS messages would be widely shared, but decrypted messages from Chinese dissidents would not be shared with China.
Old-school sovereignty just doesn't work on the Internet. If the US pushes hard enough, some firms will fold. But some may just leave. Consider the extent to which Apple has already left the US, for tax purposes.
http://www.darkreading.com/risk-management/apple-gets-patent...? (Or google for other articles)
Imagine if its WWII and that they asked for all mail to be un-sealed..Shocking but did almost happen..as far as they got was asking Military Personnel to 'volunteer' not to seal mail..
Arguably, a government can only rule over how people relate within boundaries it can defend and control. Previously the boundaries were physical geographies, and then regulated channels (mail, PSTN, etc). Now, we have a kind of fractal boundary of peer-to-peer connections that provide tremendous freedom to organize and transact on a diminishingly microscopic scale.
Sovereignty is zero sum.
Crypto provides a kind of micro-sovereignty to users, and for a few privileged or outlying people this is an acceptable risk, but when you have constituencies of people achieving that micro-sovereignty, it cuts into the sovereignty of the state at critical level.
Imagine the strategic consequences for U.S. national security if Rhode Island became it's own country, with an impenetrable laser air shield, with it's own allies, currency, tax laws, extradition treaties, defense systems, resources, etc. It would be such a constant threat, it would make more sense to just invade.
Tor and similar systems could reach that critical mass, where they become a constant threat to the sovereignty of nations. Tech is naively forcing hard questions about the conventions that provide "stability."
The feds know they might just have to just outlaw crypto. The technology exists to detect and round up most people who use it, or enough of them that it will be hard to find people to use it with. If they have to, they will.
This dance they are doing is political posturing, testing the edges to see what kind of resistance they get, and how much political capital it is going to cost.
Like voting and graffiti, if crypto really changed anything, it would be illegal.