I think Pichai is making a distinction between handing over data they already own (eg. a Gmail account) and data stored on user-controlled devices, which must be hacked to access.
Which is interesting, since he's essentially admitting that their push to send everything to "the cloud" makes their users less safe from governmental snooping (justified or not). Of course, we already knew that, but it's curious to see Google's own CEO say it.
No, Pichai is making a distinction between giving the information after a correct process and developing a backdoor to slurp the data. It has nothing to do with cloud/device differences
Aside from the non-sequitur, what Apple has been asked for is a custom build of iOS.
Really the most important part there is the "sign" step, and the fact that the FBI isn't straight-up asking for the signing keys is telling; they didn't want this request to escalate the way it has.
The precedent they want is that All Writs can be used to force Apple into creating a backdoor.
The next step is an online attack backdoor which slurps data over LTE from a suspect's device while it is unlocked.
https://assets.documentcloud.org/documents/2714001/SB-Shoote...
Some people are suggesting that Apple would create this back-doored code, and hand it to the FBI, who would then use it to access any data they want without bothering with court orders. That doesn't seem to be what the FBI are asking for.
Yes, and Apple doesn't want this as a precedent. It does away with one of their go-to selling points these days: security/privacy.
If device security can be surreptitiously undone by an OTA upgrade, what's really the point? I'm sure the brilliant legal minds at the DoJ can come up with creative interpretations to enable the next stage, which would be to do this in bulk as a special point-release.
In the case of cloud data, the government should be held to a higher standard of restriction, because all of the data is in one location, and requires only a single "factor", the identity of the target to collect data for. This applies to both "encrypted at rest" and "encrypted in flight" data.
But for data encrypted at rest on actual physical devices, there's an inherent '2-factor' security to the private invasion. The government must not only know the identity of the target to collect the information, they must possess the physical device as well. ("something you know" + "something you have")
This means, IMHO, there is far less danger, and far less scalability to "one off" hacks like the ones being requested to Apple. They don't scale to Snowden-level dragnets, they don't present low transaction cost barriers to acquisition.
The dangerous think for decentralized data is having an active attack on the device, or something which intercepts the data "in flight". These are scalable attacks you need to worry about. E.g. "push a key logger to every iphone software update"
Perhaps the law needs to make a distinction to warrants for 1-factor data vs 2-factor data, due to the inherent danger of 1-factor data, given that it scales easily to monitoring millions with little transaction cost.
So in this regard, I think there should be MORE push back for collection of cloud data, but individual one-offs for physical devices have a safer threat model.
I view this more like a Vault being found at the home of a murderer, and the cops asking the Vault maker to help unlock the Vault without revealing the proprietary locking mechanism, or without the cops needing to blow up the vault and potentially lose whats inside.
It is precisely the design of the device that the FBI wants Apple to alter using some sort of tool that Apple will make for them.
http://www.zdnet.com/article/this-is-how-the-fbi-wants-apple...